Getting Data In

How did logs from a heavy forwarder get indexed when Splunk was not running?

Madhan45
Path Finder

Splunk was running on a heavy forwarder during the time period 00:00 to 00:20. Related logs also have been found in splunkd.log & splunkd_stderr.log.
I got few logs from the HF at 23:00. How is it possible?
If Splunk is not running, how did these logs get indexed?

0 Karma

jmallorquin
Builder

Hi,

If the logs has timestamp, splunk index in the timestamp of the log. So if the log was create at 23:00, its normal that you have events in that time. Also review the timezone in which you are index the events.

Hope i help you.

0 Karma

Madhan45
Path Finder

The event generated time and index time both are same. there was no lagging in event. splunk was running only for the time period 00:00 00:20 after thet till now i didn't start splunk. then how did those logs get index?

0 Karma

jmallorquin
Builder

Open the events of the log and check if are there events from 23:00

Hope i help you

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...