<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: running down indexer congestion problems in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/running-down-indexer-congestion-problems/m-p/55608#M10868</link>
    <description>&lt;P&gt;Good advice : install the SOS app on the indexer and check the indexing performance.&lt;BR /&gt;
If the queues are full, then this can be :&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;slow disks (index queue) or congested rotation of buckets from homePath -&amp;gt; coldPath -&amp;gt; frozen&lt;/LI&gt;
&lt;LI&gt;heavy parsing (parsing/aggregation queues) or non optimized events&lt;/LI&gt;
&lt;LI&gt;heavy load, the usual suspect&lt;/LI&gt;
&lt;LI&gt;too large metadata files -&amp;gt; upgrade to 4.3 ASAP&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;And remember that at one point, you will need more than 1 indexer to scale your volume.&lt;/P&gt;</description>
    <pubDate>Wed, 14 Aug 2013 15:32:11 GMT</pubDate>
    <dc:creator>yannK</dc:creator>
    <dc:date>2013-08-14T15:32:11Z</dc:date>
    <item>
      <title>running down indexer congestion problems</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/running-down-indexer-congestion-problems/m-p/55606#M10866</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I'm running into occasional errors from one of my indexers reporting "skipped indexing of internal audit event will keep dropping events until indexer congestion is remedied. Check disk space and other issues that may cause indexer to block."&lt;/P&gt;

&lt;P&gt;I've run the following to monitor for any high values for the queues and don't see anything really actionable during timeframes I see the messages:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index="_internal" source="*metrics.log" group="queue" earliest=-4h | timechart max(current_size) span=30m by name
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Checked for any forwarders flooding my indexer and nothing was obvious. So, nothing really actionable.&lt;/P&gt;

&lt;P&gt;According to SPL-37407, this is a known issue in 4.2.1 "most often tcpout-queue", but there's no real info on how to get it addressed. in fact, that's the only place the tcpout-queue is mentioned. So, got some questions:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;is there a search to query the status of the tcpout-queue on indexers?&lt;/LI&gt;
&lt;LI&gt;would adjusting the maxQueueSize in the outputs.conf on the search heads give me a bigger default queue to work with before errors start?&lt;/LI&gt;
&lt;LI&gt;Any tips on how to troubleshoot indexer congestion issues? there's not a lot of data out there about how to handle.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Thanks!&lt;/P&gt;

&lt;P&gt;tom&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2011 22:15:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/running-down-indexer-congestion-problems/m-p/55606#M10866</guid>
      <dc:creator>tgiles</dc:creator>
      <dc:date>2011-08-09T22:15:37Z</dc:date>
    </item>
    <item>
      <title>Re: running down indexer congestion problems</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/running-down-indexer-congestion-problems/m-p/55607#M10867</link>
      <description>&lt;P&gt;You could try the "Splunk on Splunk" App, &lt;A href="http://apps.splunk.com/app/748"&gt;http://apps.splunk.com/app/748&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;It will provide you a good overview of what's happening on your indexer.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2013 14:14:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/running-down-indexer-congestion-problems/m-p/55607#M10867</guid>
      <dc:creator>splunk68</dc:creator>
      <dc:date>2013-08-14T14:14:31Z</dc:date>
    </item>
    <item>
      <title>Re: running down indexer congestion problems</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/running-down-indexer-congestion-problems/m-p/55608#M10868</link>
      <description>&lt;P&gt;Good advice : install the SOS app on the indexer and check the indexing performance.&lt;BR /&gt;
If the queues are full, then this can be :&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;slow disks (index queue) or congested rotation of buckets from homePath -&amp;gt; coldPath -&amp;gt; frozen&lt;/LI&gt;
&lt;LI&gt;heavy parsing (parsing/aggregation queues) or non optimized events&lt;/LI&gt;
&lt;LI&gt;heavy load, the usual suspect&lt;/LI&gt;
&lt;LI&gt;too large metadata files -&amp;gt; upgrade to 4.3 ASAP&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;And remember that at one point, you will need more than 1 indexer to scale your volume.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2013 15:32:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/running-down-indexer-congestion-problems/m-p/55608#M10868</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2013-08-14T15:32:11Z</dc:date>
    </item>
    <item>
      <title>Re: running down indexer congestion problems</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/running-down-indexer-congestion-problems/m-p/55609#M10869</link>
      <description>&lt;P&gt;@yannK , is it also possible for the congestion to occur due to a lot of searches targeting the indexer. We have premium apps (ITSI/ES) enabled in our environment. Could that be the case too ?&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 09:48:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/running-down-indexer-congestion-problems/m-p/55609#M10869</guid>
      <dc:creator>vr2312</dc:creator>
      <dc:date>2017-05-12T09:48:51Z</dc:date>
    </item>
  </channel>
</rss>

