Hi at all,
I'm trying to get Avamar logs by syslog (UDP).
The problem is that every time Avamar sends an event log, I don't receive in Splunk the last event, but the previous; to have the last event Avamar has to generate a new event.
In other words there is a queue problem.
I need to understand if the problem is Avamar (probably but I'm not sure) or splunk configuration.
In the second case, it'a a problem of mine!
Has anyone encountered this problem?
Thank you in advance.
Bye.
Giuseppe
↧