Splunk Enterprise Security

Log ingestion delay

tsa
New Member

We are observing delayed ingestion of logs from neuvector application, via syslog method

 

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Is the delay consistent?

What did you troubleshoot so far? Did you check whether the data which is being received on the syslog receiver (whatever you use) is "current"? Does the source have properly set time? Does your syslog receiver have properly set time? Do you have proper time parsing configuration?

0 Karma

vjdev
Path Finder

Hello,

 

Confirm the below,

 

1. No issues  with Network bandwidth [QOS]
2. Splunk Syslog/Syslog-NG/rsyslog which one are you using?
3. View the data with packet capturing, monitor the timestamp in the data.

 

0 Karma
Get Updates on the Splunk Community!

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...