Getting Data In

why some logs are missing from splunk

cyberportnoc
Explorer

zcat syslog.*.gz | grep clamav

i compare a successful one with the one who missing log in splunk,
both have clamav summary log in syslog

https://drive.google.com/file/d/0Bxs_ao6uuBDUc3hoOHVoVW5pM2c/view?usp=sharing
https://drive.google.com/file/d/0Bxs_ao6uuBDUZ2tYdzhydHNpVms/view?usp=sharing

Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi cyberportnoc,
check using a larger time period, often the problem is in differences in timestamp.
Bye.
Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi cyberportnoc,
check using a larger time period, often the problem is in differences in timestamp.
Bye.
Giuseppe

0 Karma

cyberportnoc
Explorer

i found the reason in the recorded video case,
because the host use the same host name as another host, icnetwork01
so the file actually is icnetwork01 which exist in the list

0 Karma

cyberportnoc
Explorer

after troubleshooting , i found the reasons that no log in these hosts,

some reasons that log file are locked by another process
,and some are misconfiguration of rsyslog.conf

0 Karma

cyberportnoc
Explorer

i am Martin and sent to support@splunk.com, but i do not know ssh's password of splunk,
i can only have admin right to access web, so far at night shift. is there any one needed webex to investigate this issue?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi Martin,
surely you need SSH access to splunk servers, aniway they'll contact you.
Bye.
Giuseppe

0 Karma

cyberportnoc
Explorer

i had used 7 days, still no log
these log generated every day

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi cyberportnoc,
Temporarly send your syslogs to a test index for a little period and search on this index, in this way you can be sure that you're receiving logs.
If there aren't there's a different problem to debug.
Bye.
Giuseppe

0 Karma

cyberportnoc
Explorer
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...