Splunk Cloud Platform

Why is Splunk lagging in latest logs?

sc_admin11
Explorer

In my splunk cloud , when i search for index index="asterisk" and trigger any deployment to get logs for this index and select last 15 minute to get latest logs but no logs are there. But when i change time from last 15 minute to last 6 hours then i can see my latest logs, this is weird . Log time for asterisk is in UTC.
Can someone please help me here?

Labels (1)
0 Karma

sc_admin11
Explorer

@isoutamo  logs come on time in splunk but not showing in last 15 minutes. It was showing in last 6 hour logs. Looks like some time stamp issue 

0 Karma

sc_admin11
Explorer

not getting your solution .
can you please tell me more?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

I usually do that data onboarding process with separate splunk dev/test instance to set up props.conf & transfers.conf correctly.

  • Install e..g splunk trial version to your workstation/some server (you could use also developer or dev/test license for longer period)
  • Get some sample data from your onboarding system
  • Use Splunk -> Settings -> Add Data 
    • Upload
    • Select file (your sample file)
    • Next
    • Update as need the next settings
      • Event Break
      • Timestamp
      • Advanced
    • When your events have handled properly remember save your new sourcetype definition with "Save As" button
    • Next -> Select host + index -> Review -> Submit
    • Then search events and do fixes and fine tunings if need as many times as need. You could remove events from your test index for meshing up things or use different host name to separate versions
  • After you are happy with those events then just copy your props.conf, transforms.conf and create separate TA_xyz for those. Then install it to first full splunk instance counting from UF
  • Time by time there could be some definitions on props.conf which need also install to UF too!
  • Also you could test if there are some search time props/transforms and develop those also on this host/environment. Later on install those onto your production

I hope that this clarify what I'm meaning for onboarding?

r. Ismo

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Then it's best to do onboarding process on your own test/dev instance and update props.conf to correct places after you have fixed that issue on your test splunk.

0 Karma

isoutamo
SplunkTrust
SplunkTrust
0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...