Splunk Dev

how to avoid data loss thorugh fowarder ??

rakesh_498115
Motivator

Hi...

i am using a forwader which continously forwards data to my splunk web interface..i have observed loss of data...i.e certain events are missing .i dnt know how its happening ? can you pls how can i avoid it ?? is there is any way to acknowledge whether complete data is being sent by the forwarder ??

Please help

Tags (1)

rakesh_498115
Motivator

hi mike..i found out there are missing through the splunkd log .. i could see blocked=true so many times appearing in the log for the queues...

0 Karma

mikelanghorst
Motivator

How do you know it's really missing? Your wording makes it sound like specific events rather than blocks of data. I suspect it's data that is "confusing" splunk, either due to event breaking, or maybe has multiple date fields and putting that data somewhere else in the timeline.

piebob
Splunk Employee
Splunk Employee

http://docs.splunk.com/Documentation/Splunk/latest/Data/Usepersistentqueues

i really wish you would try to read the Splunk documentation a lot more, rakesh.

piebob
Splunk Employee
Splunk Employee

Rakesh, we've asked our partner sales team to help you out, please respond to the email you've received to let them know how they can assist you.

0 Karma

rakesh_498115
Motivator

Hi Drainy...wat ever you said is right ?? since i am facing some issue with the data...i have posted the question here to get the help....can you pls respond to my question..

0 Karma

Drainy
Champion

Rakesh, I think the point that everyone is trying to make is that Splunkbase is great for people to ask questions, but not to ask stuff that is covered by the docs - the docs should be the first place you visit for your answers, y'know. Like Ayn and myself once did, we certainly didn't learn by asking every single configuration question on here 😉

rakesh_498115
Motivator

ok..even i had splunk basing trainging and admin training..but not able get few things which i am posting when required by our customers.we have been so far happy using splunk and we are trying answer our customer by seeking help from splunkbase or wat ever form is applicable..thnx 4 your advice..will get more training on due time.

0 Karma

Ayn
Legend

Its purpose is to help people solve problems, yes, but I'm very confident in that I'm far from alone in thinking there's a difference between needing help with specific issues and needing to get a general grip of how Splunk works. Please take this for what it is - a genuinely friendly advice on what I believe is the generally best way forward for you.

rakesh_498115
Motivator

Hi..Ayn...if you can help..help me in solving the problem.....the purpose splunkbase is to help ppl who are learning splunk i guess..tat is the reason i am posting my queries here...nd i am not posting similiar questions randomly ...why do i do tat if i get the ryt answer ???

0 Karma

Ayn
Legend

And re documentation rakesh, you should also consider taking Splunk training. It's a much better way of getting to grips with Splunk than throwing out more or less random questions on splunkbase.

yannK
Splunk Employee
Splunk Employee

also check the useACK=true option

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...