Splunk Cloud Platform

HI Team, We have implemented the dual ingestion for syslog servers , we can see the logs in cloud but few logs file miss

Hemant_h
Engager

We have implemented the dual ingestion for syslog servers , we can see the logs in cloud but few logs file missing and onprem have all the data  but on cloud we are missing some files which has large count of logs .
PLease help me to understand how we can get the data of those log files in splunk cloud.

Splunk cloud logs of syslog server

Hemant_h_0-1744184687952.jpeg

 

Syslog server logs on onprem

Hemant_h_1-1744184741439.jpeg

 

 

Labels (2)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Hemant_h 

What is different in term of the data flow between the two environments? How are your syslog servers sending to both on-prem and cloud Splunk instances?
Are there any TAs installed on either Splunk instance? It could be that the timestamping is incorrect rather than being missing. 

There are lots of variables at play here, please let us know as much as you can about your environment, configuration and data pipelines.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...