Getting Data In
Highlighted

Why does Splunk stop indexing data at the same day and time each week?

New Member

I use UDP 514 syslog data type. Splunk stops collecting data after same time intervals (always at 4:00 Sun), and if I edit sourcetype (only change from manual to auto) and save, data starts collecting.
Splunk 6.1 (but dosnt matter).

Tags (4)
0 Karma
Highlighted

Re: Why does Splunk stop indexing data at the same day and time each week?

Splunk Employee
Splunk Employee

The most common cause of this symptom is that the data does not stop, but lands instead at an odd place in time. I suggest using an alltime-realtime search at the problem time to review the data, or else simply searching all time for your data to find data in the future or spikes in the past to see where the data might be landing.

If that is the cause, frequently adjusting TIME_FORMAT to more accurately reflect the timestamps in your data is the solution.

There are other possible problems but they are hard to imagine from the description. This might become a support issue.

0 Karma
Highlighted

Re: Why does Splunk stop indexing data at the same day and time each week?

Explorer

Did you ever find a resolution to this issue?

0 Karma
Highlighted

Re: Why does Splunk stop indexing data at the same day and time each week?

SplunkTrust
SplunkTrust

The original poster hasn't been around for 2 years. If you have this issue, it would get you much faster and more helpful results to post your own description of your current issue, and then answer the responsive questions and comments from the community about your issue.

0 Karma
Highlighted

Re: Why does Splunk stop indexing data at the same day and time each week?

New Member

Maybe I not understood good, but after searching (hours after 4:00 Sun) it matching 0 events, till time when I "modify" sourcetype (i checked that only save is nessesery). Recently I upgraded to 6.2 version, but no change of this symptoms.

0 Karma