Splunk Enterprise Security

Log ingestion delay

tsa
New Member

We are observing delayed ingestion of logs from neuvector application, via syslog method

 

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Is the delay consistent?

What did you troubleshoot so far? Did you check whether the data which is being received on the syslog receiver (whatever you use) is "current"? Does the source have properly set time? Does your syslog receiver have properly set time? Do you have proper time parsing configuration?

0 Karma

vjdev
Path Finder

Hello,

 

Confirm the below,

 

1. No issues  with Network bandwidth [QOS]
2. Splunk Syslog/Syslog-NG/rsyslog which one are you using?
3. View the data with packet capturing, monitor the timestamp in the data.

 

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...