<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunkd's processing queues are full in Heavy Forwarder in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/splunkd-s-processing-queues-are-full-in-Heavy-Forwarder/m-p/650310#M16813</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;We are forwarding the data to Cloud instance from HWF but we don't see any data on Cloud instance. Can you suggest how to remove the blocking queues in HWF as my understand disable is the option right?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Eshwar&lt;/P&gt;</description>
    <pubDate>Thu, 13 Jul 2023 04:37:18 GMT</pubDate>
    <dc:creator>Eshwar</dc:creator>
    <dc:date>2023-07-13T04:37:18Z</dc:date>
    <item>
      <title>splunkd's processing queues are full in Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunkd-s-processing-queues-are-full-in-Heavy-Forwarder/m-p/650090#M16793</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;We have recently installed Heavy Forwarder and disabled the indexing on it and also we are not forwarding any data from forwarders as of now but all the queue are full in HWF. Don't understand how HWF is full simply without getting any data. Please suggest how to clear them and make it as normal.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Eshwar_0-1689143031022.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26216i72C36F378C9DCF01/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Eshwar_0-1689143031022.png" alt="Eshwar_0-1689143031022.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Eshwar&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2023 06:26:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunkd-s-processing-queues-are-full-in-Heavy-Forwarder/m-p/650090#M16793</guid>
      <dc:creator>Eshwar</dc:creator>
      <dc:date>2023-07-12T06:26:26Z</dc:date>
    </item>
    <item>
      <title>Re: splunkd's processing queues are full in Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunkd-s-processing-queues-are-full-in-Heavy-Forwarder/m-p/650191#M16800</link>
      <description>&lt;P&gt;Are you sure the HF is not forwarding any data?&amp;nbsp; By default, it will send its own logs.&amp;nbsp; btool can show what inputs are enabled.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splunk btool inputs list --debug&lt;/LI-CODE&gt;&lt;P&gt;The fix is to remove whatever is blocking the queues.&amp;nbsp; In this case, make sure the HF has indexers to send to.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2023 13:53:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunkd-s-processing-queues-are-full-in-Heavy-Forwarder/m-p/650191#M16800</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-07-12T13:53:58Z</dc:date>
    </item>
    <item>
      <title>Re: splunkd's processing queues are full in Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunkd-s-processing-queues-are-full-in-Heavy-Forwarder/m-p/650310#M16813</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;We are forwarding the data to Cloud instance from HWF but we don't see any data on Cloud instance. Can you suggest how to remove the blocking queues in HWF as my understand disable is the option right?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Eshwar&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2023 04:37:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunkd-s-processing-queues-are-full-in-Heavy-Forwarder/m-p/650310#M16813</guid>
      <dc:creator>Eshwar</dc:creator>
      <dc:date>2023-07-13T04:37:18Z</dc:date>
    </item>
    <item>
      <title>Re: splunkd's processing queues are full in Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunkd-s-processing-queues-are-full-in-Heavy-Forwarder/m-p/650392#M16820</link>
      <description>&lt;P&gt;The HF should be logging messages about why it can't send to Splunk Cloud.&amp;nbsp; Please share those messages so we can suggest solutions.&amp;nbsp; Once that is resolved, the queues will decrease.&lt;/P&gt;&lt;P&gt;Confirm your network allows connections from the HF to your Splunk Cloud indexers.&lt;/P&gt;&lt;P&gt;Verify you have installed the "Universal Forwarder" app from your Splunk Cloud instance on the HF.&amp;nbsp; Yes, an app called "Universal Forwarder" really does go on a Heavy Forwarder.&lt;/P&gt;&lt;P&gt;Disabling inputs will prevent more data from being added to the queues, but will not clear the queues.&amp;nbsp; Restarting the HF will clear the in-memory queues, however.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2023 14:42:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunkd-s-processing-queues-are-full-in-Heavy-Forwarder/m-p/650392#M16820</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-07-13T14:42:48Z</dc:date>
    </item>
  </channel>
</rss>

