All Apps and Add-ons

Are there time look back limitations when exporting data from Splunk Hadoop Connect?

_gkollias
Builder

Hi!

While using Splunk Hadoop Connect to export data from Splunk to Hadoop, we've observed export functionality halts once we reach 254 days ago. We have 14 months of summary data that we'd like to export, but are unable to go back any further.

Here are some references in the documentation we've been using to test:

http://docs.splunk.com/Documentation/HadoopConnect/1.2.5/DeployHadoopConnect/Configurationfilerefere...

https://docs.splunk.com/Documentation/HadoopConnect/1.2.5/DeployHadoopConnect/ExporttoHDFS#How_data_...

Also, we've also made sure to stay in line with file size limitations. Are there any known limitations to how far back we can go to export data? Any insight is greatly appreciated.

Thanks in advance!

0 Karma
1 Solution

sloshburch
Splunk Employee
Splunk Employee

Sounds like either a bug or other symptoms we've not yet seen:

  • Bug: Open a Support Case since it's not working as documented
  • Error Message: Before support case, make sure there's no error messages in _internal or the related sources from the hadoop connect. It's possible Splunk is dying on something related to the content and we just didn't notice that error.

Lastly, there are some alternatives to this functionality depending on the purpose of using it:

(I thought there was more, but now my mind is blank, so we'll start with this).

View solution in original post

sloshburch
Splunk Employee
Splunk Employee

Sounds like either a bug or other symptoms we've not yet seen:

  • Bug: Open a Support Case since it's not working as documented
  • Error Message: Before support case, make sure there's no error messages in _internal or the related sources from the hadoop connect. It's possible Splunk is dying on something related to the content and we just didn't notice that error.

Lastly, there are some alternatives to this functionality depending on the purpose of using it:

(I thought there was more, but now my mind is blank, so we'll start with this).

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...