Getting Data In

Why does Splunk stop indexing data at the same day and time each week?

ksiaze
New Member

I use UDP 514 syslog data type. Splunk stops collecting data after same time intervals (always at 4:00 Sun), and if I edit sourcetype (only change from manual to auto) and save, data starts collecting.
Splunk 6.1 (but dosnt matter).

Tags (4)
0 Karma

ksiaze
New Member

Maybe I not understood good, but after searching (hours after 4:00 Sun) it matching 0 events, till time when I "modify" sourcetype (i checked that only save is nessesery). Recently I upgraded to 6.2 version, but no change of this symptoms.

0 Karma

jrodman
Splunk Employee
Splunk Employee

The most common cause of this symptom is that the data does not stop, but lands instead at an odd place in time. I suggest using an alltime-realtime search at the problem time to review the data, or else simply searching all time for your data to find data in the future or spikes in the past to see where the data might be landing.

If that is the cause, frequently adjusting TIME_FORMAT to more accurately reflect the timestamps in your data is the solution.

There are other possible problems but they are hard to imagine from the description. This might become a support issue.

0 Karma

marciniega
Explorer

Did you ever find a resolution to this issue?

0 Karma

DalJeanis
Legend

The original poster hasn't been around for 2 years. If you have this issue, it would get you much faster and more helpful results to post your own description of your current issue, and then answer the responsive questions and comments from the community about your issue.

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...