Quantcast
Channel: Questions in topic: "universal-forwarder"
Viewing all articles
Browse latest Browse all 1551

How to troubleshoot why data is only getting indexed in Splunk for 1 hour every day with no interval specified in inputs.conf?

$
0
0
Hi, We have an issue with Splunk getting data into indexes. We are getting data only during one hour (12.00 AM to 12.59 AM) every day. We have not specified any interval though in inputs.conf. Can you please advise why it is restricting indexing to this one hour? Please note that we have data in log files, verified our Universal forwarders side. Thanks

Viewing all articles
Browse latest Browse all 1551

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>