Getting Data In

Why is indexer ingesting firewall logs every 4 hours instead of up to the minute?

Lwoods
Path Finder

Hello,

I have a syslog server ingesting device logs which are sent from the deployment server, and then to the indexer. My esxi as well as other devices are sending logs every minute.  However, my firewall logs are only ingested every 4 hours on the indexer.  Could this be a latency issue, or is it the firewall causing the problem?

 

Thank you

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Lwoods ,

I suppose that your Deployment Server has to manage less than 50 clients, otherwise it isn't correct to use the DS as syslog server.

Anyway, maybe this could be the issue.

Then, when you say that you receive logs every 4 hours, are you menaing the thy receive syslogs every four hours and you lost syslogs in the other periods or that you continously ingest syslogs but the DS send them to Indexers every 4 hours?

Ciao.

Giuseppe 

Lwoods
Path Finder

My syslog is handling all devices that can't have forwarders on them, like switches routers, etc.  It store all device logs for a limited time and the syslog sends them directly to their respective indexes.   On the indexer, I view all latest events from each index that is being received from the syslog.   The latest events for my switches, routers, etc are are all reporting the latest events in minutes.  Whereas, the firewall is reporting the latest event 4 hours ago. 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Lwoods ,

I can suppose that you receive by syslog events from devices without Forwarder.

AS I said, the question is has your Deployment Server to manage more or less than 50 Forwarders?

if more, it must be on a dedicated server and you cannot use it as syslog server.

Anyway, if you have all the logs but with a delay of 4 hours, did you checked the Timezone, maybe the difference is on this.

Ciao.

Giuseppe 

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...