Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

universal forwarder delay - 8 minutes

$
0
0
Any ideas why I am seeing an 8 minute delay in the UF -> Index data? The UF is monitoring a logfile that is consistently generating realtime data. When I view the index from my SH, I am unable to see anything before 8 minutes. I am currently using a cluster: 1SH, (1indx+1indx) RF2 SF2 cluster, Master, UF w/ index autodiscover set ... And it seems all other index are reacting in the same way so I am assuming this is a global setting somewhere. I'm currently reading up on limits.conf and pipeline/parallel parellization. Thank You, Sean

Viewing all articles
Browse latest Browse all 47296

Trending Articles