Getting Data In

Why is indexer ingesting firewall logs every 4 hours instead of up to the minute?

Lwoods
Path Finder

Hello,

I have a syslog server ingesting device logs which are sent from the deployment server, and then to the indexer. My esxi as well as other devices are sending logs every minute.  However, my firewall logs are only ingested every 4 hours on the indexer.  Could this be a latency issue, or is it the firewall causing the problem?

 

Thank you

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Lwoods ,

I suppose that your Deployment Server has to manage less than 50 clients, otherwise it isn't correct to use the DS as syslog server.

Anyway, maybe this could be the issue.

Then, when you say that you receive logs every 4 hours, are you menaing the thy receive syslogs every four hours and you lost syslogs in the other periods or that you continously ingest syslogs but the DS send them to Indexers every 4 hours?

Ciao.

Giuseppe 

Lwoods
Path Finder

My syslog is handling all devices that can't have forwarders on them, like switches routers, etc.  It store all device logs for a limited time and the syslog sends them directly to their respective indexes.   On the indexer, I view all latest events from each index that is being received from the syslog.   The latest events for my switches, routers, etc are are all reporting the latest events in minutes.  Whereas, the firewall is reporting the latest event 4 hours ago. 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Lwoods ,

I can suppose that you receive by syslog events from devices without Forwarder.

AS I said, the question is has your Deployment Server to manage more or less than 50 Forwarders?

if more, it must be on a dedicated server and you cannot use it as syslog server.

Anyway, if you have all the logs but with a delay of 4 hours, did you checked the Timezone, maybe the difference is on this.

Ciao.

Giuseppe 

Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...