Getting Data In

Why does Splunk stop indexing data at the same day and time each week?

ksiaze
New Member

I use UDP 514 syslog data type. Splunk stops collecting data after same time intervals (always at 4:00 Sun), and if I edit sourcetype (only change from manual to auto) and save, data starts collecting.
Splunk 6.1 (but dosnt matter).

Tags (4)
0 Karma

ksiaze
New Member

Maybe I not understood good, but after searching (hours after 4:00 Sun) it matching 0 events, till time when I "modify" sourcetype (i checked that only save is nessesery). Recently I upgraded to 6.2 version, but no change of this symptoms.

0 Karma

jrodman
Splunk Employee
Splunk Employee

The most common cause of this symptom is that the data does not stop, but lands instead at an odd place in time. I suggest using an alltime-realtime search at the problem time to review the data, or else simply searching all time for your data to find data in the future or spikes in the past to see where the data might be landing.

If that is the cause, frequently adjusting TIME_FORMAT to more accurately reflect the timestamps in your data is the solution.

There are other possible problems but they are hard to imagine from the description. This might become a support issue.

0 Karma

marciniega
Explorer

Did you ever find a resolution to this issue?

0 Karma

DalJeanis
SplunkTrust
SplunkTrust

The original poster hasn't been around for 2 years. If you have this issue, it would get you much faster and more helpful results to post your own description of your current issue, and then answer the responsive questions and comments from the community about your issue.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...