I'm in the middle of doing historical data migration form on-prem indexers to S3 in Splunk Cloud. Some of the data is making it through, but I'm getting a ton of these type messages in splunkd.log on the on-prem indexers: WARN S3Client - Error getting object name = <...GUID/receipt.json(0,-1,) to localPath = /opt/splunk/var/run/splunk/cachemanager/receipt-(some numbers.json>
... View more
I performed this search:
| datamodel Authentication Autherntication search | search Authentication.src=xxx.yyy.com (over past 60 min)
the results took 6.26 min
the search against raw:
index=* xxx.yyy.com
and the same number of results only took 10 seconds to return...
... View more