Getting Data In

Why is some of my Data Not Onboarding After Writing Input.conf file?

Prakash493
Communicator

Hi , i have a problem. i wrote one input.conf file and half of the data has been onboarded, and i can see the data in Splunk. But rest of half of the data from same input.conf file hasn't been onboarded. I thought it might be a firewall issue or networking, but if so, then half of the data is also not going to be onboarded.

pls help me out.

Tags (1)
0 Karma

mstjohn_splunk
Splunk Employee
Splunk Employee

hi @Prakash493,

DId you get a chance to consider @richgalloway 's question? It sounds like the community needs some more info to fully understand your question. When you get a chance, go ahead and leave a comment explaining your issue further!

0 Karma

DalJeanis
Legend

Another possibility is that either your _time is being parsed incorrectly on the missing events or the events are not properly breaking. Thus, some show up correctly and some do not.

0 Karma

ddrillic
Ultra Champion

Right right, in some of these sub-cases, you can find the events by searching in the future ....

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If you are getting some data then it's likely not a firewall or networking problem.

Please share the relevant stanzas from your inputs.conf and props.conf files as well as some sample data.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...