Hi,
(Sorry for my English, I'm French)
I send my logs via syslog on port 514 or 40514 and I have a problem with this new system.
I send 10 tests (logger) and I receive only 9. If I send 5, I receive 4. If I send 19, I receive 18 (always missing the last one on this new system).
When I use TCPDump, to see what is send and I have always 10 if test is 10, 5 is test is 5..... All my log is send but in the Splunk Search engine, I miss the last? I dont know why, its very strange....
I get more than 50 systems and the problem is only on this new system.
It's the same system for another question here: http://answers.splunk.com/answers/230364/french-syslog.html
(I have 2 UF with VIP, 1 indexer, 1 search engine and 1 for management)
What you thought? Are there other tests that I could do?
Do you have a track for help me to try to correct this problem?
Thank you
... View more