Splunk Search

Why is the latest event indexed 4 days ago when server logs show current data?

taylorl
Explorer

Hi,

I have an issue currently where the last event was 4 days ago. I have checked the server logs manually and I can see we have a lot that splunk can not see. I think the service accounts were changed to a new one and then back to their accounts which leads me to believe this is the cause of the issue I am facing now.

Can anyone point me in the right direction on where to look to start troubleshooting? Restarting the services has been done and I can confirm they have been put back to the original starting ones.

Cheers!

Tags (3)
1 Solution

taylorl
Explorer

Actually I have just figured it out. Turns out the UNIVERSAL FORWARD service had been stopped. Restarted that and it's now working.

I should have also mentioned in my original post I had an UNIVERSAL FORWARD.

View solution in original post

0 Karma

taylorl
Explorer

Actually I have just figured it out. Turns out the UNIVERSAL FORWARD service had been stopped. Restarted that and it's now working.

I should have also mentioned in my original post I had an UNIVERSAL FORWARD.

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...