Splunk Cloud Platform

Inconsistent data injestion Lansweeper

PolarBear01
Engager

Hi everyone,

I've recently integrated Lansweeper (cloud) data into my Splunk Cloud instance, but over the past few days, I've been encountering some ingestion issues.

I used the add-on: https://splunkbase.splunk.com/app/5418

Specifically, the data source intermittently stops sending data to Splunk without any clear pattern. Here's what I've checked so far:

  • My configuration seems fine, and the polling interval is set to 300 seconds.
  • The ingestion behavior appears inconsistent, as seen in the attached image. Based on the type of data Lansweeper generates, I wouldn't expect this inconsistency.
  • While double-checking my configuration, I noticed an error, yet the source still manages to ingest data sporadically at certain hours.

 

PolarBear01_0-1734510256951.png

PolarBear01_2-1734510538747.png

Has anyone experienced similar issues or could provide guidance on how to debug this further?

Thanks in advance for your help!

LansweeperLansweeper Add-on for SplunkLansweeper Add On For Splunk 

Labels (1)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @PolarBear01 i am not sure how to help on this, but thought to ask you:

1) did you enter only one site or multiple sites?

2) as shown on that error text, may i know, if had a chance to check the python.log for more details

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

PolarBear01
Engager

Hi @inventsekar, thanks for the reply,

I just entered one site. On the other hand I would be pleased to share the error logs but none are showing.
I configured logging level on the app as "ERROR" and "DEBUG" but no logs appear when I run:
index=_internal source="/opt/splunk/var/log/splunk/python.log" level!=INFO

Regards,

PB

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...