Getting Data In

splunk logs missing for a particular timeframe

Prakash493
Communicator

Hi I have an issue , i have a gap in splunk logs for a 20 minute , i saw my splunk universal forwarder is up and running , collecting logs but for a 20 min period it didnt ingest any logs then after some time it again ingest logs , how do i find what happend on that 20 minute period also how can i recover those logs which went missing for 20 minutes.

0 Karma
1 Solution

adonio
Ultra Champion

for troubleshooting, start with:
index=_internal host=<youtForwarder> log_level = WARN* OR log_level=error
for the rest, look at this link:
https://docs.splunk.com/Documentation/Splunk/7.2.6/Troubleshooting/Cantfinddata

View solution in original post

0 Karma

adonio
Ultra Champion

for troubleshooting, start with:
index=_internal host=<youtForwarder> log_level = WARN* OR log_level=error
for the rest, look at this link:
https://docs.splunk.com/Documentation/Splunk/7.2.6/Troubleshooting/Cantfinddata

0 Karma
Get Updates on the Splunk Community!

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...

New Dates, New City: Save the Date for .conf25!

Wake up, babe! New .conf25 dates AND location just dropped!! That's right, this year, .conf25 is taking place ...

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...