Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Splunk data are cut of randomly

$
0
0
I am having problem with UF data ingestion. There are 36 servers (18 server are prod and 18 are test-prod) I have deployment server who deploy configuration files to the 36 servers. But the logs i get are incomplete from different server. "incomplete" means most server send complete logs but other servers logs are being cut. **Example logs: (Complete)** + server-service applicationservice-engine1:status server-service: applicationservice-engine1: OK + server-service applicationservice-engine2:status server-service: applicationservice-engine2: OK **(incomplete sample 1)** + server-service applicationservice-engine2:status server-service: applicationservice-engine2: OK **(incomplete sample 2)** server-service: applicationservice-engine1: OK + server-service applicationservice-engine2:status server-service: applicationservice-engine2: OK **my inputs.conf :** [monitor:///var/log/scripts/service-status.log] disabled = 0 index = operations sourcetype = service:status and there are **NO** Props or Transforms applied. What may be the reason of this occurrence?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>