<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to troubleshoot why Windows event forwarders are reporting typing and parsingqueue blocked messages, causing delayed forwarding and indexing? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-Windows-event-forwarders-are-reporting/m-p/284723#M54393</link>
    <description>&lt;P&gt;Is this indicating a problem on the forwarders, or the indexers?  I don't really see any way to determine that...&lt;/P&gt;

&lt;P&gt;My indexers are loaded with resources - 48 cpu's and 256gb of memory, so I'd be very surprised if that's the issue.  This particular forwarder processes event logs, at about 7 - 10k per minute.  &lt;/P&gt;</description>
    <pubDate>Tue, 31 May 2016 22:20:37 GMT</pubDate>
    <dc:creator>a212830</dc:creator>
    <dc:date>2016-05-31T22:20:37Z</dc:date>
    <item>
      <title>How to troubleshoot why Windows event forwarders are reporting typing and parsingqueue blocked messages, causing delayed forwarding and indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-Windows-event-forwarders-are-reporting/m-p/284721#M54391</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I've had complaints from customers that data is taking too long to appear in the system. Today, one of the Windows event forwarders was 2 hours behind...   I looked for "blocked" messages, and see lots of typing queue and parsingqueue blocked messages. How can I troubleshoot these?  Are there any settings that can be configured to help?  (I'm at Splunk 6.1.9).&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2016 21:53:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-Windows-event-forwarders-are-reporting/m-p/284721#M54391</guid>
      <dc:creator>a212830</dc:creator>
      <dc:date>2016-05-31T21:53:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why Windows event forwarders are reporting typing and parsingqueue blocked messages, causing delayed forwarding and indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-Windows-event-forwarders-are-reporting/m-p/284722#M54392</link>
      <description>&lt;P&gt;Sometimes this happens when your CPU or Memory Usage is too high on the forwarders, or even the indexers.&lt;/P&gt;

&lt;P&gt;Check your CPU usage and load averages, etc.  If they are too high, you may need to upgrade some systems.&lt;/P&gt;

&lt;P&gt;Or maybe even you need to optimize some large searches, etc.&lt;/P&gt;

&lt;P&gt;A common cause of this is monitoring a super large folder like this:&lt;/P&gt;

&lt;P&gt;[monitor://path/.../*.log]&lt;/P&gt;

&lt;P&gt;You're effectively telling splunk to index everything under /path thats a .log file but maybe there are billions of files in this directory that are .txt files, etc.  Splunk has to keep a running list of what it's already processed, etc. and things get messy... especially on non-reference hardware such as 1 CPU virtual machines, etc.&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2016 22:14:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-Windows-event-forwarders-are-reporting/m-p/284722#M54392</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2016-05-31T22:14:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why Windows event forwarders are reporting typing and parsingqueue blocked messages, causing delayed forwarding and indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-Windows-event-forwarders-are-reporting/m-p/284723#M54393</link>
      <description>&lt;P&gt;Is this indicating a problem on the forwarders, or the indexers?  I don't really see any way to determine that...&lt;/P&gt;

&lt;P&gt;My indexers are loaded with resources - 48 cpu's and 256gb of memory, so I'd be very surprised if that's the issue.  This particular forwarder processes event logs, at about 7 - 10k per minute.  &lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2016 22:20:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-Windows-event-forwarders-are-reporting/m-p/284723#M54393</guid>
      <dc:creator>a212830</dc:creator>
      <dc:date>2016-05-31T22:20:37Z</dc:date>
    </item>
  </channel>
</rss>

