<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why are indexing queues full on the search head, but nothing has been indexing? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexing-queues-full-on-the-search-head-but-nothing-has/m-p/337312#M62311</link>
    <description>&lt;P&gt;Do you have an outputs.conf on your SH that forwards its logs to your indexers?&lt;/P&gt;</description>
    <pubDate>Fri, 28 Jul 2017 20:11:30 GMT</pubDate>
    <dc:creator>esix_splunk</dc:creator>
    <dc:date>2017-07-28T20:11:30Z</dc:date>
    <item>
      <title>Why are indexing queues full on the search head, but nothing has been indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexing-queues-full-on-the-search-head-but-nothing-has/m-p/337303#M62302</link>
      <description>&lt;P&gt;Hey Guys,&lt;/P&gt;

&lt;P&gt;So, I've got a weird one. According to my monitoring console, the indexing queues on my search head are all pegged at 100%, and have been for a long time. The thing is, nothing's indexing on the thing. It's forwarding internal logs to my indexers, and I'm not running any Summary indexes on it.&lt;/P&gt;

&lt;P&gt;Is there a way to figure out what's blocking it up? It's not a huge priority beyond the fact that the system is slow compared to other search heads, and that my boss wants to figure out why it's flagging; partially for academic reasons. Only thing I really have to go on is that on the search head, it's showing my corporate_security role with read access when I check the Introspection API; something that's not on any other system including other search heads.&lt;/P&gt;

&lt;P&gt;Note, I don't have a Search Head cluster, but I am running a clustered pair of Indexers.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2017 17:45:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexing-queues-full-on-the-search-head-but-nothing-has/m-p/337303#M62302</guid>
      <dc:creator>Haybuck15</dc:creator>
      <dc:date>2017-07-28T17:45:39Z</dc:date>
    </item>
    <item>
      <title>Re: Why are indexing queues full on the search head, but nothing has been indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexing-queues-full-on-the-search-head-but-nothing-has/m-p/337304#M62303</link>
      <description>&lt;P&gt;any errors or warning in internal index for that particular search head?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2017 19:33:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexing-queues-full-on-the-search-head-but-nothing-has/m-p/337304#M62303</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-07-28T19:33:52Z</dc:date>
    </item>
    <item>
      <title>Re: Why are indexing queues full on the search head, but nothing has been indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexing-queues-full-on-the-search-head-but-nothing-has/m-p/337305#M62304</link>
      <description>&lt;P&gt;Nope, none whatsoever. In fact, the largest index on that search head is 3 MB; and that's only because it did some self-indexing before I configured it when it was originally stood up.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2017 19:39:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexing-queues-full-on-the-search-head-but-nothing-has/m-p/337305#M62304</guid>
      <dc:creator>Haybuck15</dc:creator>
      <dc:date>2017-07-28T19:39:52Z</dc:date>
    </item>
    <item>
      <title>Re: Why are indexing queues full on the search head, but nothing has been indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexing-queues-full-on-the-search-head-but-nothing-has/m-p/337306#M62305</link>
      <description>&lt;P&gt;the search head outputs its data&lt;BR /&gt;
try and search;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index = _ internal host = "yourQueuedSearchHead" log_level = warn* OR log_level = error
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;any results&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2017 19:41:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexing-queues-full-on-the-search-head-but-nothing-has/m-p/337306#M62305</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-07-28T19:41:57Z</dc:date>
    </item>
    <item>
      <title>Re: Why are indexing queues full on the search head, but nothing has been indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexing-queues-full-on-the-search-head-but-nothing-has/m-p/337307#M62306</link>
      <description>&lt;P&gt;So, it looks like the search is coming back empty, however I can do the same for every other instance of Splunk in the deployment. Is it possible that the indexing queues would fill up if it can't forward its internal logs? I mean, I wouldn't think so.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2017 19:45:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexing-queues-full-on-the-search-head-but-nothing-has/m-p/337307#M62306</guid>
      <dc:creator>Haybuck15</dc:creator>
      <dc:date>2017-07-28T19:45:28Z</dc:date>
    </item>
    <item>
      <title>Re: Why are indexing queues full on the search head, but nothing has been indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexing-queues-full-on-the-search-head-but-nothing-has/m-p/337308#M62307</link>
      <description>&lt;P&gt;wild guess here,&lt;BR /&gt;
check available disk space on this particular search head&lt;BR /&gt;
if theres no space, or very minimal it can prevent splunk from indexing locally and sending the data from the search heads to indexers layer&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2017 19:50:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexing-queues-full-on-the-search-head-but-nothing-has/m-p/337308#M62307</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-07-28T19:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: Why are indexing queues full on the search head, but nothing has been indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexing-queues-full-on-the-search-head-but-nothing-has/m-p/337309#M62308</link>
      <description>&lt;P&gt;296 GB / 299 GB Free, so that's not it.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2017 19:52:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexing-queues-full-on-the-search-head-but-nothing-has/m-p/337309#M62308</guid>
      <dc:creator>Haybuck15</dc:creator>
      <dc:date>2017-07-28T19:52:38Z</dc:date>
    </item>
    <item>
      <title>Re: Why are indexing queues full on the search head, but nothing has been indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexing-queues-full-on-the-search-head-but-nothing-has/m-p/337310#M62309</link>
      <description>&lt;P&gt;There's a typo in adonio's search.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index = _internal host = "yourQueuedSearchHead" log_level = warn* OR log_level = error
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 28 Jul 2017 19:55:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexing-queues-full-on-the-search-head-but-nothing-has/m-p/337310#M62309</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2017-07-28T19:55:15Z</dc:date>
    </item>
    <item>
      <title>Re: Why are indexing queues full on the search head, but nothing has been indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexing-queues-full-on-the-search-head-but-nothing-has/m-p/337311#M62310</link>
      <description>&lt;P&gt;I typed it by hand, I didn't copy paste it, so that's not the issue. Just doing the below search pulls back nothing.&lt;/P&gt;

&lt;P&gt;index=_* host="yourQueuedSearchHead"&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2017 20:03:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexing-queues-full-on-the-search-head-but-nothing-has/m-p/337311#M62310</guid>
      <dc:creator>Haybuck15</dc:creator>
      <dc:date>2017-07-28T20:03:33Z</dc:date>
    </item>
    <item>
      <title>Re: Why are indexing queues full on the search head, but nothing has been indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexing-queues-full-on-the-search-head-but-nothing-has/m-p/337312#M62311</link>
      <description>&lt;P&gt;Do you have an outputs.conf on your SH that forwards its logs to your indexers?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2017 20:11:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexing-queues-full-on-the-search-head-but-nothing-has/m-p/337312#M62311</guid>
      <dc:creator>esix_splunk</dc:creator>
      <dc:date>2017-07-28T20:11:30Z</dc:date>
    </item>
    <item>
      <title>Re: Why are indexing queues full on the search head, but nothing has been indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexing-queues-full-on-the-search-head-but-nothing-has/m-p/337313#M62312</link>
      <description>&lt;P&gt;Yes, yes I do. I in fact have one on every Splunk system in the environment that's not a Universal Forwarder.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2017 20:13:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexing-queues-full-on-the-search-head-but-nothing-has/m-p/337313#M62312</guid>
      <dc:creator>Haybuck15</dc:creator>
      <dc:date>2017-07-28T20:13:14Z</dc:date>
    </item>
    <item>
      <title>Re: Why are indexing queues full on the search head, but nothing has been indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexing-queues-full-on-the-search-head-but-nothing-has/m-p/337314#M62313</link>
      <description>&lt;P&gt;May be you can try clearing dispatch directory or increase indexingqueue size.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2017 20:45:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexing-queues-full-on-the-search-head-but-nothing-has/m-p/337314#M62313</guid>
      <dc:creator>sbbadri</dc:creator>
      <dc:date>2017-07-28T20:45:00Z</dc:date>
    </item>
    <item>
      <title>Re: Why are indexing queues full on the search head, but nothing has been indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexing-queues-full-on-the-search-head-but-nothing-has/m-p/337315#M62314</link>
      <description>&lt;P&gt;Are you replacing "yourQueuedSearchHead" with the host name of your queued search head?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2017 21:30:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexing-queues-full-on-the-search-head-but-nothing-has/m-p/337315#M62314</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2017-07-28T21:30:43Z</dc:date>
    </item>
    <item>
      <title>Re: Why are indexing queues full on the search head, but nothing has been indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexing-queues-full-on-the-search-head-but-nothing-has/m-p/337316#M62315</link>
      <description>&lt;P&gt;Are ports/ACL/routes in place to allow for your Search Head to send to your indexers (9997/9998)?&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jul 2017 04:17:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-indexing-queues-full-on-the-search-head-but-nothing-has/m-p/337316#M62315</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-07-30T04:17:05Z</dc:date>
    </item>
  </channel>
</rss>

