Getting Data In

Why does Splunk stop indexing data at the same day and time each week?

ksiaze
New Member

I use UDP 514 syslog data type. Splunk stops collecting data after same time intervals (always at 4:00 Sun), and if I edit sourcetype (only change from manual to auto) and save, data starts collecting.
Splunk 6.1 (but dosnt matter).

Tags (4)
0 Karma

ksiaze
New Member

Maybe I not understood good, but after searching (hours after 4:00 Sun) it matching 0 events, till time when I "modify" sourcetype (i checked that only save is nessesery). Recently I upgraded to 6.2 version, but no change of this symptoms.

0 Karma

jrodman
Splunk Employee
Splunk Employee

The most common cause of this symptom is that the data does not stop, but lands instead at an odd place in time. I suggest using an alltime-realtime search at the problem time to review the data, or else simply searching all time for your data to find data in the future or spikes in the past to see where the data might be landing.

If that is the cause, frequently adjusting TIME_FORMAT to more accurately reflect the timestamps in your data is the solution.

There are other possible problems but they are hard to imagine from the description. This might become a support issue.

0 Karma

marciniega
Explorer

Did you ever find a resolution to this issue?

0 Karma

DalJeanis
Legend

The original poster hasn't been around for 2 years. If you have this issue, it would get you much faster and more helpful results to post your own description of your current issue, and then answer the responsive questions and comments from the community about your issue.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...