Hi All,
Good Day.
Need help in Splunk data receiving.
We have Avamar backup node which is sending the data to splunk is in EST time zone.
The splunk server is configured with the UTC time zone.
The data is being received by splunk which shows the correct time but when the index server parsing the data, thinking it was 4 hours old data and ignoring it. So backup failures are not captured and ticket is not generating for backup failures.
Upon verifiying in splunk side, some of the received data between _time & indextime difference of 4 hours and some of them receving correctly. When the difference time is 4 hours splunk is ignoring the data and not generating ticket for failures.
Note: The search is running for every 15 minutes if we increase the search duration to see last 4 hours then we will receive lot of duplicates.
We have contacted Dell support but they are updating me that backup application just send the data with the MIB file as it when receives the data. It would be the splunk to process the data correctly.
Please help to solve the issue and any recommendation is appreciated.
... View more