Splunk Cloud Platform

Inconsistent data injestion Lansweeper

PolarBear01
Engager

Hi everyone,

I've recently integrated Lansweeper (cloud) data into my Splunk Cloud instance, but over the past few days, I've been encountering some ingestion issues.

I used the add-on: https://splunkbase.splunk.com/app/5418

Specifically, the data source intermittently stops sending data to Splunk without any clear pattern. Here's what I've checked so far:

  • My configuration seems fine, and the polling interval is set to 300 seconds.
  • The ingestion behavior appears inconsistent, as seen in the attached image. Based on the type of data Lansweeper generates, I wouldn't expect this inconsistency.
  • While double-checking my configuration, I noticed an error, yet the source still manages to ingest data sporadically at certain hours.

 

PolarBear01_0-1734510256951.png

PolarBear01_2-1734510538747.png

Has anyone experienced similar issues or could provide guidance on how to debug this further?

Thanks in advance for your help!

LansweeperLansweeper Add-on for SplunkLansweeper Add On For Splunk 

Labels (1)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @PolarBear01 i am not sure how to help on this, but thought to ask you:

1) did you enter only one site or multiple sites?

2) as shown on that error text, may i know, if had a chance to check the python.log for more details

0 Karma

PolarBear01
Engager

Hi @inventsekar, thanks for the reply,

I just entered one site. On the other hand I would be pleased to share the error logs but none are showing.
I configured logging level on the app as "ERROR" and "DEBUG" but no logs appear when I run:
index=_internal source="/opt/splunk/var/log/splunk/python.log" level!=INFO

Regards,

PB

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...