Getting Data In

Why is indexer ingesting firewall logs every 4 hours instead of up to the minute?

Lwoods
Path Finder

Hello,

I have a syslog server ingesting device logs which are sent from the deployment server, and then to the indexer. My esxi as well as other devices are sending logs every minute.  However, my firewall logs are only ingested every 4 hours on the indexer.  Could this be a latency issue, or is it the firewall causing the problem?

 

Thank you

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Lwoods ,

I suppose that your Deployment Server has to manage less than 50 clients, otherwise it isn't correct to use the DS as syslog server.

Anyway, maybe this could be the issue.

Then, when you say that you receive logs every 4 hours, are you menaing the thy receive syslogs every four hours and you lost syslogs in the other periods or that you continously ingest syslogs but the DS send them to Indexers every 4 hours?

Ciao.

Giuseppe 

Lwoods
Path Finder

My syslog is handling all devices that can't have forwarders on them, like switches routers, etc.  It store all device logs for a limited time and the syslog sends them directly to their respective indexes.   On the indexer, I view all latest events from each index that is being received from the syslog.   The latest events for my switches, routers, etc are are all reporting the latest events in minutes.  Whereas, the firewall is reporting the latest event 4 hours ago. 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Lwoods ,

I can suppose that you receive by syslog events from devices without Forwarder.

AS I said, the question is has your Deployment Server to manage more or less than 50 Forwarders?

if more, it must be on a dedicated server and you cannot use it as syslog server.

Anyway, if you have all the logs but with a delay of 4 hours, did you checked the Timezone, maybe the difference is on this.

Ciao.

Giuseppe 

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...