We have implemented the dual ingestion for syslog servers , we can see the logs in cloud but few logs file missing and onprem have all the data but on cloud we are missing some files which has large count of logs .
PLease help me to understand how we can get the data of those log files in splunk cloud.
Splunk cloud logs of syslog server
Syslog server logs on onprem
Hi @Hemant_h
What is different in term of the data flow between the two environments? How are your syslog servers sending to both on-prem and cloud Splunk instances?
Are there any TAs installed on either Splunk instance? It could be that the timestamping is incorrect rather than being missing.
There are lots of variables at play here, please let us know as much as you can about your environment, configuration and data pipelines.
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing