Splunk Search

Why is the latest event indexed 4 days ago when server logs show current data?

taylorl
Explorer

Hi,

I have an issue currently where the last event was 4 days ago. I have checked the server logs manually and I can see we have a lot that splunk can not see. I think the service accounts were changed to a new one and then back to their accounts which leads me to believe this is the cause of the issue I am facing now.

Can anyone point me in the right direction on where to look to start troubleshooting? Restarting the services has been done and I can confirm they have been put back to the original starting ones.

Cheers!

Tags (3)
1 Solution

taylorl
Explorer

Actually I have just figured it out. Turns out the UNIVERSAL FORWARD service had been stopped. Restarted that and it's now working.

I should have also mentioned in my original post I had an UNIVERSAL FORWARD.

View solution in original post

0 Karma

taylorl
Explorer

Actually I have just figured it out. Turns out the UNIVERSAL FORWARD service had been stopped. Restarted that and it's now working.

I should have also mentioned in my original post I had an UNIVERSAL FORWARD.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...