Splunk Search

Delayed log ingestion

cymondcuba
New Member

Hi Splunk,

Having a problem with one of our ingestion in splunk. The logs are delayed and cant seem to find the cause of the ingestion issue. Could someone help us what would be the troubleshooting to be done? and what might be causing the issue as the logs are delayed for a day.

Thank you,

Tags (1)
0 Karma

gjanders
SplunkTrust
SplunkTrust

There are various places this could happen, at the indexer level you should be looking at your monitoring console , are the event pipelines blocked?

At the forwarder level, you can check this via the splunkd.log file which will advise if the throttling limit for the forwarder has been reached or not, and if you are not just reaching a throttle limit which you can change in limits.conf you could then look into your metrics.log on the forwarder to see if limits are reached there.

Are your forwarders connecting directly to indexers? If not you can use the monitoring console to check the next heavy forwarder in the chain before it gets to the indexer if that is the case.

The Splunk conf 2017 had a few sessions around troubleshooting which might help here, note I've added some filters there you may wish to turn them off / change them to find more sessions...

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...