Getting Data In

Why is UBA data stopping send data

zksvc
Contributor

Hi everyone,

 

I’m investigating an issue where UBA (User Behavior Analytics) data in Splunk appears to have stopped ingesting or processing after October 11, 2025, even though today is October 14, 2025.

 

As shown in the screenshot, I ran this search:

index=ueba earliest=-7d | stats count by _time | sort - _time
 

The results show the latest _time entries are from 2025-10-11, with no events recorded on the 12th, 13th, or 14th. The time range of the search correctly spans from Oct 7 to Oct 14, so it’s not a time filter issue.

 

I’ve verified that:

  • Other indexes are receiving data normally.
  • The UBA app is enabled and licensed.
  • No recent configuration changes were made to UBA or its inputs.
 

Has anyone experienced this before? Could this be related to:

  • A known UBA ingestion delay or bug?
  • Timezone misconfiguration?
  • Data pipeline failure (e.g., forwarder, indexer, or UBA collector)?
  • Scheduled maintenance or throttling?
 

Any guidance or troubleshooting steps would be greatly appreciated!

 

Thanks in advance!

 

last-log-11-oct.pnglast-log-11-oct.png

Labels (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

The sort command has a default limit. Try this instead

| sort 0 - _time
0 Karma

zksvc
Contributor

Thanks for your reply, but it not work 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Your screenshot shows a green dot by the job dropdown. What message do you get when you click this?

0 Karma

zksvc
Contributor

Hey sorry for late reply, all is good since i do stop-all and start-all 

i don't really know the issue is

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...