<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Index Processor: The index processor has paused data flow. Too many tsidx files in.... in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Index-Processor-The-index-processor-has-paused-data-flow-Too/m-p/433416#M20429</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have recently inherited a Splunk Enterprise (v6.6) instance with some serious issues. The architecture is a distributed one with the Search head, Indexer and Heavy Forwarder all residing on different hosts. The primary problem I am facing is that after a short period of the time the queues (parsing, aggregator, typing and index) reach 100% and result in the error mentioned in the title.&lt;/P&gt;

&lt;P&gt;Upon investigating the Index file directory where the errors are reported, there are 100+ .lock files that seem to replicate as file.lock, file.lock.lock, file.lock.lock.lock etc etc.&lt;/P&gt;

&lt;P&gt;The machines that are running Splunk have more than enough RAM,CPU and IOPS. I have manually run splunk-optimize with no effect. I am lost on what to do next and almost considering deleting the index (not preferred) to resolve this issue.&lt;/P&gt;

&lt;P&gt;Any help would be much appreciated.&lt;/P&gt;</description>
    <pubDate>Wed, 29 Aug 2018 00:03:34 GMT</pubDate>
    <dc:creator>alex387</dc:creator>
    <dc:date>2018-08-29T00:03:34Z</dc:date>
    <item>
      <title>Index Processor: The index processor has paused data flow. Too many tsidx files in....</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Index-Processor-The-index-processor-has-paused-data-flow-Too/m-p/433416#M20429</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have recently inherited a Splunk Enterprise (v6.6) instance with some serious issues. The architecture is a distributed one with the Search head, Indexer and Heavy Forwarder all residing on different hosts. The primary problem I am facing is that after a short period of the time the queues (parsing, aggregator, typing and index) reach 100% and result in the error mentioned in the title.&lt;/P&gt;

&lt;P&gt;Upon investigating the Index file directory where the errors are reported, there are 100+ .lock files that seem to replicate as file.lock, file.lock.lock, file.lock.lock.lock etc etc.&lt;/P&gt;

&lt;P&gt;The machines that are running Splunk have more than enough RAM,CPU and IOPS. I have manually run splunk-optimize with no effect. I am lost on what to do next and almost considering deleting the index (not preferred) to resolve this issue.&lt;/P&gt;

&lt;P&gt;Any help would be much appreciated.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Aug 2018 00:03:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Index-Processor-The-index-processor-has-paused-data-flow-Too/m-p/433416#M20429</guid>
      <dc:creator>alex387</dc:creator>
      <dc:date>2018-08-29T00:03:34Z</dc:date>
    </item>
    <item>
      <title>Re: Index Processor: The index processor has paused data flow. Too many tsidx files in....</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Index-Processor-The-index-processor-has-paused-data-flow-Too/m-p/433417#M20430</link>
      <description>&lt;P&gt;where are the queues pile up? indexer or heavy forwarder?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Aug 2018 00:34:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Index-Processor-The-index-processor-has-paused-data-flow-Too/m-p/433417#M20430</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2018-08-29T00:34:24Z</dc:date>
    </item>
    <item>
      <title>Re: Index Processor: The index processor has paused data flow. Too many tsidx files in....</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Index-Processor-The-index-processor-has-paused-data-flow-Too/m-p/433418#M20431</link>
      <description>&lt;P&gt;Starts at the Heavy Forwarder and once it is maxed out, it then flows onto the indexer until it is 100% m&lt;/P&gt;</description>
      <pubDate>Wed, 29 Aug 2018 00:40:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Index-Processor-The-index-processor-has-paused-data-flow-Too/m-p/433418#M20431</guid>
      <dc:creator>alex387</dc:creator>
      <dc:date>2018-08-29T00:40:15Z</dc:date>
    </item>
  </channel>
</rss>

