Same problem here,
I got logs working for a while and then stops indexing without reason, splunk keep receiving logs so the counter keep increase but last log received is stop to a couple of hours ago, depends when stops.
I just have 10 mikrotik devices, nothing else. I have the same problem on windows machine, linux and docker running on synology.
Checking with wireshark the logs are coming in correctly from the devices.
I don't know how to resolve, I reinstalled splunk so many times now!!
... View more