Hi , i have a problem. i wrote one input.conf file and half of the data has been onboarded, and i can see the data in Splunk. But rest of half of the data from same input.conf file hasn't been onboarded. I thought it might be a firewall issue or networking, but if so, then half of the data is also not going to be onboarded.
pls help me out.
hi @Prakash493,
DId you get a chance to consider @richgalloway 's question? It sounds like the community needs some more info to fully understand your question. When you get a chance, go ahead and leave a comment explaining your issue further!
Another possibility is that either your _time
is being parsed incorrectly on the missing events or the events are not properly breaking. Thus, some show up correctly and some do not.
Right right, in some of these sub-cases, you can find the events by searching in the future ....
If you are getting some data then it's likely not a firewall or networking problem.
Please share the relevant stanzas from your inputs.conf and props.conf files as well as some sample data.