Hi All,
I have 10 index. But in1 index logs were not being indexed frequently.
Restarting HF fixing this issue for few days. And again same issue persist. How to find root cause of this issue and fix this permanently.
@isoutamo @saravanan90 @thambisetty @ITWhisperer @gcusello @bowesmana @to4kawa
@thambisetty Input is through monitor from Forwarder.
In splunkd.log i can see only recent logs. I want to find rca in yesterday's log. Can u help here?
what kind of input are you referring above. is that monitor or network or script?