Hi,
We could observe that there is a Delay in event log processing from Splunk forwarders to Syslog by three hours, what is the reason causing this delay and how can we rectify it??
I would start from these: https://docs.splunk.com/Documentation/Splunk/7.3.1/Troubleshooting/Troubleshootingeventsindexingdela...
https://docs.splunk.com/Documentation/Splunk/7.3.1/Troubleshooting/Troubleshootindexingperformance
Thanks...!! Will check on this..