I have a problem with the logs, they are arriving with a delay of 12 hours or more
The information first reaches a syslog server and is forwarded to the indexers
When reviewing the logs in the syslog servers I find that they arrive without problem and with the correct date and time
when I go to the indexers or search heads to look at the logs I see that they have a delay of 12 hours or more
With this document I have tried to diagnose the problem but I cannot find the same panels that ask to review the document
in the part where it is suggested to check with the command iostat -zx 1 one of the parameters are in the values cataloged as bad
splunkcol_1-1601562510064.png
splunkcol_0-1601561959333.pngWhat else should I check?
splunkcol_2-1601562619818.png
yes, the syslog server receives the logs and forwards them to the indexers using UF
I understand that the cause of the queuing is typingqueue?
splunkcol_0-1601577492282.png
In a previous post you suggested that I check that it will have a minimum IOPS, after checking, the disk has more than 800, it even has double.