<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk index congestion is happening in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-index-congestion-is-happening/m-p/273730#M21842</link>
    <description>&lt;P&gt;Did you check indexer disk space?&lt;BR /&gt;
Assuming that's fine, continue with the distributed management console to see if you actually have indexer congestion or if your forwarder/search head is just confused.&lt;BR /&gt;
If everything's showing as blocked in DMC, check for relevant error messages on the indexers.&lt;/P&gt;</description>
    <pubDate>Sat, 10 Sep 2016 17:46:00 GMT</pubDate>
    <dc:creator>martin_mueller</dc:creator>
    <dc:date>2016-09-10T17:46:00Z</dc:date>
    <item>
      <title>Splunk index congestion is happening</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-index-congestion-is-happening/m-p/273729#M21841</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
I suddenly got this message "skipped indexing of internal audit event will keep dropping events until indexer congestion is remedied. Check disk space and other issues that may cause indexer to block"&lt;BR /&gt;
I am not able to index data can anyone suggest me how to solve this.&lt;/P&gt;</description>
      <pubDate>Sat, 10 Sep 2016 12:44:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-index-congestion-is-happening/m-p/273729#M21841</guid>
      <dc:creator>sravani387</dc:creator>
      <dc:date>2016-09-10T12:44:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk index congestion is happening</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-index-congestion-is-happening/m-p/273730#M21842</link>
      <description>&lt;P&gt;Did you check indexer disk space?&lt;BR /&gt;
Assuming that's fine, continue with the distributed management console to see if you actually have indexer congestion or if your forwarder/search head is just confused.&lt;BR /&gt;
If everything's showing as blocked in DMC, check for relevant error messages on the indexers.&lt;/P&gt;</description>
      <pubDate>Sat, 10 Sep 2016 17:46:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-index-congestion-is-happening/m-p/273730#M21842</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2016-09-10T17:46:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk index congestion is happening</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-index-congestion-is-happening/m-p/273731#M21843</link>
      <description>&lt;P&gt;A good response for this case at &lt;A href="https://answers.splunk.com/answers/44552/indexing-congestion-consistenly-happening.html"&gt;indexing congestion consistenly happening&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;It says -&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/1825i58709706E9453139/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 10 Sep 2016 23:54:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-index-congestion-is-happening/m-p/273731#M21843</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-09-10T23:54:47Z</dc:date>
    </item>
  </channel>
</rss>

