Splunk Enterprise Security

Log ingestion delay

tsa
New Member

We are observing delayed ingestion of logs from neuvector application, via syslog method

 

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Is the delay consistent?

What did you troubleshoot so far? Did you check whether the data which is being received on the syslog receiver (whatever you use) is "current"? Does the source have properly set time? Does your syslog receiver have properly set time? Do you have proper time parsing configuration?

0 Karma

vjdev
Path Finder

Hello,

 

Confirm the below,

 

1. No issues  with Network bandwidth [QOS]
2. Splunk Syslog/Syslog-NG/rsyslog which one are you using?
3. View the data with packet capturing, monitor the timestamp in the data.

 

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...