Splunk Search

Delayed log ingestion

cymondcuba
New Member

Hi Splunk,

Having a problem with one of our ingestion in splunk. The logs are delayed and cant seem to find the cause of the ingestion issue. Could someone help us what would be the troubleshooting to be done? and what might be causing the issue as the logs are delayed for a day.

Thank you,

Tags (1)
0 Karma

gjanders
SplunkTrust
SplunkTrust

There are various places this could happen, at the indexer level you should be looking at your monitoring console , are the event pipelines blocked?

At the forwarder level, you can check this via the splunkd.log file which will advise if the throttling limit for the forwarder has been reached or not, and if you are not just reaching a throttle limit which you can change in limits.conf you could then look into your metrics.log on the forwarder to see if limits are reached there.

Are your forwarders connecting directly to indexers? If not you can use the monitoring console to check the next heavy forwarder in the chain before it gets to the indexer if that is the case.

The Splunk conf 2017 had a few sessions around troubleshooting which might help here, note I've added some filters there you may wish to turn them off / change them to find more sessions...

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...