Getting Data In

Why is Splunk cutting off the data received with collect command?

benhurbarbieri
New Member

Splunk is cutting some data that is received through collect made on a server.

I have already reviewed the props.conf and inputs.conf files.

Has anyone seen anything about this?

Thankful.

0 Karma

nadlurinadluri
Communicator

Ideally collect command is used only for statistical data, and I dont exactly understand as on what data is missing once you use collect command!! Can you elaborate?

pruthvikrishnap
Contributor

Hi Ben,
Try adding the complete values to your search try mentioning the complete index, source-type etc.

| collect index=summary sourcetype=foo

Re-check if any regex is applied on any field.
Share few samples on what is missing, may be we can look into it.
Let me know if this helps.

horsefez
Motivator

Hi @benhurbarbieri,

it's not so clear what you are talking about, but I guess you are talking about Event-Breaking.
Maybe data is coming in and the event isn't breaking at the timestamp you configured.
Stuff like that is pretty common.

To help you, you need to post some sample data and the corresponding stanza's in props/transforms.conf if there are any.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...