In my splunk cloud , when i search for index index="asterisk" and trigger any deployment to get logs for this index and select last 15 minute to get latest logs but no logs are there. But when i change time from last 15 minute to last 6 hours then i can see my latest logs, this is weird . Log time for asterisk is in UTC.
Can someone please help me here?
@isoutamo logs come on time in splunk but not showing in last 15 minutes. It was showing in last 6 hour logs. Looks like some time stamp issue
not getting your solution .
can you please tell me more?
I usually do that data onboarding process with separate splunk dev/test instance to set up props.conf & transfers.conf correctly.
I hope that this clarify what I'm meaning for onboarding?
r. Ismo
Then it's best to do onboarding process on your own test/dev instance and update props.conf to correct places after you have fixed that issue on your test splunk.
Hi
here is couple of answers/presentations/hints how to find the real issue and fix it
There are lot more those instructions how to find the reason behind that lag.
r. Ismo