Coming soon - Get a detailed view of why an account is flagged as spam!
view details

This post has been de-listed

It is no longer included in search results and normal feeds (front page, hot posts, subreddit posts, etc). It remains visible only via the author's post history.

1
Slow indexing? - for one host (~25min behind)?
Post Body

So I'm not 100% sure where in my splunk system I should be looking. I am gathering logs from two paloalto's on a linux box, syslog-ng and then a universalforwarder is picking it up and sending it into splunk.

It is not a big system, 8 cpu,16gb of ram, ~ 30gb of daily indexing.

If I do a search for just the host, It is showing data was received ~25 min ago, but nothing sense. If I go to monitoring, and forwarder instance it shows data has been received from that same server less then a minute ago.

So I'm guessing this means it's taking 25min to index the data once it's received. Yet the CPU is running at maybe 20% if not less. And if I'm looking at it correctly the queue's are showing 0 items in the queue.

Author
Account Strength
100%
Account Age
6 years
Verified Email
Yes
Verified Flair
No
Total Karma
8,278
Link Karma
565
Comment Karma
7,603
Profile updated: 6 days ago
Posts updated: 3 months ago

Subreddit

Post Details

We try to extract some basic information from the post title. This is not always successful or accurate, please use your best judgement and compare these values to the post title and body for confirmation.
Posted
3 years ago