Splunk Search

Why is the latest event indexed 4 days ago when server logs show current data?

taylorl
Explorer

Hi,

I have an issue currently where the last event was 4 days ago. I have checked the server logs manually and I can see we have a lot that splunk can not see. I think the service accounts were changed to a new one and then back to their accounts which leads me to believe this is the cause of the issue I am facing now.

Can anyone point me in the right direction on where to look to start troubleshooting? Restarting the services has been done and I can confirm they have been put back to the original starting ones.

Cheers!

Tags (3)
1 Solution

taylorl
Explorer

Actually I have just figured it out. Turns out the UNIVERSAL FORWARD service had been stopped. Restarted that and it's now working.

I should have also mentioned in my original post I had an UNIVERSAL FORWARD.

View solution in original post

0 Karma

taylorl
Explorer

Actually I have just figured it out. Turns out the UNIVERSAL FORWARD service had been stopped. Restarted that and it's now working.

I should have also mentioned in my original post I had an UNIVERSAL FORWARD.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...