Splunk Cloud Platform

HI Team, We have implemented the dual ingestion for syslog servers , we can see the logs in cloud but few logs file miss

Hemant_h
Engager

We have implemented the dual ingestion for syslog servers , we can see the logs in cloud but few logs file missing and onprem have all the data  but on cloud we are missing some files which has large count of logs .
PLease help me to understand how we can get the data of those log files in splunk cloud.

Splunk cloud logs of syslog server

Hemant_h_0-1744184687952.jpeg

 

Syslog server logs on onprem

Hemant_h_1-1744184741439.jpeg

 

 

Labels (2)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Hemant_h 

What is different in term of the data flow between the two environments? How are your syslog servers sending to both on-prem and cloud Splunk instances?
Are there any TAs installed on either Splunk instance? It could be that the timestamping is incorrect rather than being missing. 

There are lots of variables at play here, please let us know as much as you can about your environment, configuration and data pipelines.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...