<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forwarding of data dies in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-of-data-dies/m-p/231940#M45192</link>
    <description>&lt;P&gt;Also just FYI the UFs are are running Linux on Splunk 6.3.3 but upgrading has no affect on this issue&lt;BR /&gt;
All other servers including Splunk HWFs and Indexers are 6.4.3&lt;/P&gt;</description>
    <pubDate>Wed, 05 Oct 2016 16:58:36 GMT</pubDate>
    <dc:creator>tkwaller</dc:creator>
    <dc:date>2016-10-05T16:58:36Z</dc:date>
    <item>
      <title>Forwarding of data dies</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-of-data-dies/m-p/231939#M45191</link>
      <description>&lt;P&gt;Have about 1000 UFs that not getting data that is searchable&lt;BR /&gt;
They are throwing the error:&lt;BR /&gt;
10-05-2016 14:54:05.162 +0000 INFO  TailReader - Could not send data to output queue (parsingQueue), retrying...&lt;BR /&gt;
10-05-2016 14:54:10.163 +0000 INFO  TailReader -   ...continuing.&lt;BR /&gt;
10-05-2016 14:54:20.165 +0000 INFO  TailReader - Could not send data to output queue (parsingQueue), retrying...&lt;BR /&gt;
10-05-2016 14:54:25.166 +0000 INFO  TailReader -   ...continuing.&lt;/P&gt;

&lt;P&gt;All hosts have unlimited thruput to our HWFs that also have unlimited thruput to the indexers. Our HWFs have dual pipelines so its not blocking there for sure. We have about 2800 UFs forwarding to 24 HWFs that forward to 28 or so Indexers.&lt;/P&gt;

&lt;P&gt;Via the DMC I can see our queues are basically 0 so it shows no data backup.&lt;/P&gt;

&lt;P&gt;Any idea what the issue could be?&lt;/P&gt;

&lt;P&gt;Thanks for the thoughts!&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2016 16:51:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-of-data-dies/m-p/231939#M45191</guid>
      <dc:creator>tkwaller</dc:creator>
      <dc:date>2016-10-05T16:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding of data dies</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-of-data-dies/m-p/231940#M45192</link>
      <description>&lt;P&gt;Also just FYI the UFs are are running Linux on Splunk 6.3.3 but upgrading has no affect on this issue&lt;BR /&gt;
All other servers including Splunk HWFs and Indexers are 6.4.3&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2016 16:58:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-of-data-dies/m-p/231940#M45192</guid>
      <dc:creator>tkwaller</dc:creator>
      <dc:date>2016-10-05T16:58:36Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding of data dies</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-of-data-dies/m-p/231941#M45193</link>
      <description>&lt;P&gt;This has intermittently been ongoing for MONTHS since installing 6.4.1 on Splunk Admin servers, search heads, HWFs and indexers.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2016 17:00:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-of-data-dies/m-p/231941#M45193</guid>
      <dc:creator>tkwaller</dc:creator>
      <dc:date>2016-10-05T17:00:17Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding of data dies</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-of-data-dies/m-p/231942#M45194</link>
      <description>&lt;P&gt;Hey, &lt;/P&gt;

&lt;P&gt;I work on the same team as @Tkwaller. Restarting the Universal Forwarder often makes the problem go away for days but eventually resurfaces. &lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2016 17:34:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-of-data-dies/m-p/231942#M45194</guid>
      <dc:creator>daniel333</dc:creator>
      <dc:date>2016-10-05T17:34:18Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding of data dies</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-of-data-dies/m-p/231943#M45195</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Nice deployment &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;You should probably start by opening a case to Splunk support. &lt;BR /&gt;
However some links that may be interesting for you:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/5590/could-not-send-data-to-the-output-queue.html"&gt;https://answers.splunk.com/answers/5590/could-not-send-data-to-the-output-queue.html&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://splunkgeek.blogspot.co.uk/2015/05/could-not-send-data-to-output-queue.html"&gt;http://splunkgeek.blogspot.co.uk/2015/05/could-not-send-data-to-output-queue.html&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://wiki.splunk.com/Community:HowIndexingWorks"&gt;http://wiki.splunk.com/Community:HowIndexingWorks&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Most probably you would need to investigate things that are running in the UF side, are there complex regex ? huge amount of files being monitored and so on.&lt;/P&gt;

&lt;P&gt;If none of the queues on HFW/indexers have high usage of their queues, then the investigation shall focus on UFW and the job they're doing.&lt;/P&gt;

&lt;P&gt;You said upgrading does not help, have you tried upgrading a group of UFs to 6.4.x for testing purposes ? &lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2016 19:29:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-of-data-dies/m-p/231943#M45195</guid>
      <dc:creator>guilmxm</dc:creator>
      <dc:date>2016-10-05T19:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding of data dies</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-of-data-dies/m-p/231944#M45196</link>
      <description>&lt;P&gt;The root cause of this was a HWF that also runs as a syslog collector. For some reason the HWF becomes too busy and stops.&lt;BR /&gt;
It is still undetermined HOW this 1 HWF could stop the entire flow of data through the entire environment  though, as there are many others that should have taken over.&lt;BR /&gt;
For now the issue is fixed&lt;/P&gt;</description>
      <pubDate>Fri, 07 Oct 2016 15:16:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-of-data-dies/m-p/231944#M45196</guid>
      <dc:creator>tkwaller</dc:creator>
      <dc:date>2016-10-07T15:16:30Z</dc:date>
    </item>
  </channel>
</rss>

