Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Splunk not ingesting last event

$
0
0
We are currently ingesting our historical data, but we may have found a defect/bug. When we drop a month worth of files for a batch input, there are a few files where the last event does not get ingested. To test, I deleted the specific source file where the count did not compare and reingested it, the counts then matched and the last event got ingested. Could anyone explain why the last event of the occasional source file (dropped along side with 20+ other files) does not get ingested?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>