<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic forwarder dropping events in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/forwarder-dropping-events/m-p/152639#M31068</link>
    <description>&lt;P&gt;Currently, I have 2 seperate clusters. One 'old' 6.0 cluster, and a new cluster for 6.2.&lt;BR /&gt;
The idea is to have our forwarders forwarding to both clusters at the same time. I modified the outputs.conf on the forwarders, and can see events coming in on both clusters. So far, so good.&lt;/P&gt;

&lt;P&gt;When I take a closer look, I can see events dropping on most forwarders:&lt;BR /&gt;
index=_internal sourcetype=splunkd "has begun dropping events"&lt;/P&gt;

&lt;P&gt;I can't find the root cause of this. No queues are blocked, network seems to be ok, and the indexers (both clusters) are fine too. Also, when I look closer on the local queues, I cannot see any alarming levels as well. No throtteling either (no maxkbps messages)&lt;BR /&gt;
index=_internal source="/opt/splunkforwarder/var/log/splunk/metrics.log" group=queue current_size_kb&amp;gt;0&lt;/P&gt;

&lt;P&gt;Only message that occurs frequently is "File descriptor cache is full (100), trimming". For what I could find, it should be regarderd as an informational message, not really harming anything.&lt;/P&gt;

&lt;P&gt;Who can help me out to find the actual bottleneck?&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 20:14:58 GMT</pubDate>
    <dc:creator>renems</dc:creator>
    <dc:date>2020-09-28T20:14:58Z</dc:date>
    <item>
      <title>forwarder dropping events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forwarder-dropping-events/m-p/152639#M31068</link>
      <description>&lt;P&gt;Currently, I have 2 seperate clusters. One 'old' 6.0 cluster, and a new cluster for 6.2.&lt;BR /&gt;
The idea is to have our forwarders forwarding to both clusters at the same time. I modified the outputs.conf on the forwarders, and can see events coming in on both clusters. So far, so good.&lt;/P&gt;

&lt;P&gt;When I take a closer look, I can see events dropping on most forwarders:&lt;BR /&gt;
index=_internal sourcetype=splunkd "has begun dropping events"&lt;/P&gt;

&lt;P&gt;I can't find the root cause of this. No queues are blocked, network seems to be ok, and the indexers (both clusters) are fine too. Also, when I look closer on the local queues, I cannot see any alarming levels as well. No throtteling either (no maxkbps messages)&lt;BR /&gt;
index=_internal source="/opt/splunkforwarder/var/log/splunk/metrics.log" group=queue current_size_kb&amp;gt;0&lt;/P&gt;

&lt;P&gt;Only message that occurs frequently is "File descriptor cache is full (100), trimming". For what I could find, it should be regarderd as an informational message, not really harming anything.&lt;/P&gt;

&lt;P&gt;Who can help me out to find the actual bottleneck?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 20:14:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forwarder-dropping-events/m-p/152639#M31068</guid>
      <dc:creator>renems</dc:creator>
      <dc:date>2020-09-28T20:14:58Z</dc:date>
    </item>
    <item>
      <title>Re: forwarder dropping events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forwarder-dropping-events/m-p/152640#M31069</link>
      <description>&lt;P&gt;Might be useful, the actual error msg:&lt;BR /&gt;
06-10-2015 14:00:25.833 +0200 INFO  TcpOutputProc - Queue for group splunknw has begun dropping events&lt;BR /&gt;
06-10-2015 14:00:25.833 +0200 INFO  TcpOutputProc - Queue for group splunknw has stopped dropping events&lt;BR /&gt;
06-10-2015 14:00:34.829 +0200 INFO  TcpOutputProc - Queue for group splunknw has begun dropping events&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2015 14:16:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forwarder-dropping-events/m-p/152640#M31069</guid>
      <dc:creator>renems</dc:creator>
      <dc:date>2015-06-10T14:16:28Z</dc:date>
    </item>
    <item>
      <title>Re: forwarder dropping events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forwarder-dropping-events/m-p/521613#M88130</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/63819"&gt;@renems&lt;/a&gt;&amp;nbsp;, were you&amp;nbsp; able to find any&amp;nbsp; root cause with this???&lt;/P&gt;</description>
      <pubDate>Sat, 26 Sep 2020 15:46:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forwarder-dropping-events/m-p/521613#M88130</guid>
      <dc:creator>hectorvp</dc:creator>
      <dc:date>2020-09-26T15:46:41Z</dc:date>
    </item>
    <item>
      <title>Re: forwarder dropping events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forwarder-dropping-events/m-p/563135#M100334</link>
      <description>&lt;P&gt;2nd such post with no resolution &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Aug 2021 03:13:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forwarder-dropping-events/m-p/563135#M100334</guid>
      <dc:creator>dm1</dc:creator>
      <dc:date>2021-08-13T03:13:02Z</dc:date>
    </item>
  </channel>
</rss>

