Initially we were using splunk enterprise to log our real time logs. But few days before we have moved onto splunk cloud for logging.
And also have migrated all the alerts and dashboards from splunk enterprise to splunk cloud.
Now we are observing that there is a lag in logs sent to splunk cloud.
As logs are getting delayed for few minutes on splunk cloud compared to splunk enterprise. Need to understand what's the reason can someone please guide
Hi
what you are meaning with "lagging behind logging"? _time is wrong or there are delays before log events are usable on SC or something else?
r. Ismo