Splunk: troubleshooting missing, late and mis-parsed data
Splunk's own troubleshooting manuals as a routine for the most common complaint, 'my data isn't there': check index, permissions and time range; prove whether forwarders connect using Splunk's internal logs; fix forwarder and receiver port mistakes, blocked queues and throughput limits; use btool to see which configuration file wins; and correct timestamps, time zones and line breaking, which decide where events land in time. Includes indexing delay and what licence warnings and violations do.
- Level
- Advanced
- Length
- About 50 minutes
- Contents
- 3 lessons · 1 video · final exam
- Status
- Published · updated 2 Oct 2026
- Splunk
Skills you'll practise
- Work through Splunk's 'I can't find my data' checks: index, role permissions, time range, forwarders, search heads, licence and the query
- Prove whether a forwarder is connected using _internal metrics and splunkd.log, and fix receiving-port mistakes
- Use btool with --debug to find which file sets a configuration value, and know its limitation
- Explain timestamp and time zone precedence and where those props.conf settings must live
- Measure indexing delay with _indextime and match the pattern to a cause
- Describe what happens to indexing and searching during a licence violation
Course outline
- 1.Splunk: finding missing and late dataVideo · 2 min
- 2.'I can't find my data': the first checksLesson · 16 min
- 3.Forwarders, receivers, queues and btoolLesson · 17 min
- 4.Timestamps, time zones, line breaking, delay and licenceLesson · 17 min
- 5.Splunk: troubleshooting missing, late and mis-parsed data: knowledge checkKnowledge check · 17 questions
- 6.Final exam9 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- Splunk Enterprise Troubleshooting Manual: I can't find my data!
- Splunk Enterprise Troubleshooting Manual: Use btool to troubleshoot configurations
- Splunk Enterprise Troubleshooting Manual: What Splunk software logs about itself
- Splunk Enterprise Troubleshooting Manual: Event indexing delay
- Splunk Enterprise Forwarding Data: Troubleshoot forwarder/receiver connection
- Splunk Universal Forwarder Manual: Troubleshoot the universal forwarder
- Splunk Enterprise Getting Data In: How timestamp assignment works
- Splunk Enterprise Getting Data In: Specify time zones for timestamps
- Splunk Enterprise Getting Data In: Configure event line breaking
- Splunk Enterprise Admin Manual: About license violations
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.