Getting Data In

Why does Splunk stop indexing data at the same day and time each week?

ksiaze
New Member

I use UDP 514 syslog data type. Splunk stops collecting data after same time intervals (always at 4:00 Sun), and if I edit sourcetype (only change from manual to auto) and save, data starts collecting.
Splunk 6.1 (but dosnt matter).

Tags (4)
0 Karma

ksiaze
New Member

Maybe I not understood good, but after searching (hours after 4:00 Sun) it matching 0 events, till time when I "modify" sourcetype (i checked that only save is nessesery). Recently I upgraded to 6.2 version, but no change of this symptoms.

0 Karma

jrodman
Splunk Employee
Splunk Employee

The most common cause of this symptom is that the data does not stop, but lands instead at an odd place in time. I suggest using an alltime-realtime search at the problem time to review the data, or else simply searching all time for your data to find data in the future or spikes in the past to see where the data might be landing.

If that is the cause, frequently adjusting TIME_FORMAT to more accurately reflect the timestamps in your data is the solution.

There are other possible problems but they are hard to imagine from the description. This might become a support issue.

0 Karma

marciniega
Explorer

Did you ever find a resolution to this issue?

0 Karma

DalJeanis
Legend

The original poster hasn't been around for 2 years. If you have this issue, it would get you much faster and more helpful results to post your own description of your current issue, and then answer the responsive questions and comments from the community about your issue.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...