Skip to main content

Site CollectorSite Collector Administration Guide

Table of Contents

Only a few of the installed Splunk Collectors are processing logs or EPS has dropped by 50% as compared to last hour

Solution: For all the Splunk Collectors to process the logs:

  • Check the accessibility of the Splunk server.

  • Verify if the logs are coming to the Splunk server for all Splunk queries.

  • Check whether queries are changed for this Splunk collectors.

  • Ensure that there is a log volume available for processing on the Splunk server for the associated Splunk queries. Usually, a Site Collector with several Splunk collectors processes up to 7K EPS.

  • Review the bigger queries to optimize log processing.