<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Parsing Queue blocked on Heavy Forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Parsing-Queue-blocked-on-Heavy-Forwarder/m-p/495056#M84464</link>
    <description>&lt;P&gt;The issue appears to be at the aggQueue based on the screenshot.&lt;BR /&gt;
So check if the props.conf is configured correctly for the sourcetypes.&lt;BR /&gt;
Things you want to check:&lt;BR /&gt;
- Should_Linemerge&lt;BR /&gt;
- Max_events&lt;BR /&gt;
- Time_prefix&lt;BR /&gt;
- Time_format&lt;BR /&gt;
- Datetime_config&lt;BR /&gt;
- Max_Days_Ago&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 04:34:23 GMT</pubDate>
    <dc:creator>anmolpatel</dc:creator>
    <dc:date>2020-09-30T04:34:23Z</dc:date>
    <item>
      <title>Parsing Queue blocked on Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Parsing-Queue-blocked-on-Heavy-Forwarder/m-p/495055#M84463</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;

&lt;P&gt;I got some question regarding parsing queue issues I have been observing on our Heavy Forwarders. I am currently seeing between 500 and 1000 blocked events on each heavy forwarder daily when running:&lt;/P&gt;

&lt;P&gt;index=_internal host=&lt;EM&gt;HF&lt;/EM&gt; blocked=true &lt;/P&gt;

&lt;P&gt;The total ratio of blocked events seems to be about 10% and they mostly all seem to appear in the aggqueue:&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/8546iD5D45A8F282D573B/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;My main question is if this is reason for concern or what the impact on my current Splunk environment would be. Also why would all this blocking be in mainly one queue ?&lt;/P&gt;

&lt;P&gt;Thank you,&lt;/P&gt;

&lt;P&gt;Oliver&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2020 13:17:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Parsing-Queue-blocked-on-Heavy-Forwarder/m-p/495055#M84463</guid>
      <dc:creator>omuelle1</dc:creator>
      <dc:date>2020-03-12T13:17:03Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing Queue blocked on Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Parsing-Queue-blocked-on-Heavy-Forwarder/m-p/495056#M84464</link>
      <description>&lt;P&gt;The issue appears to be at the aggQueue based on the screenshot.&lt;BR /&gt;
So check if the props.conf is configured correctly for the sourcetypes.&lt;BR /&gt;
Things you want to check:&lt;BR /&gt;
- Should_Linemerge&lt;BR /&gt;
- Max_events&lt;BR /&gt;
- Time_prefix&lt;BR /&gt;
- Time_format&lt;BR /&gt;
- Datetime_config&lt;BR /&gt;
- Max_Days_Ago&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:34:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Parsing-Queue-blocked-on-Heavy-Forwarder/m-p/495056#M84464</guid>
      <dc:creator>anmolpatel</dc:creator>
      <dc:date>2020-09-30T04:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing Queue blocked on Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Parsing-Queue-blocked-on-Heavy-Forwarder/m-p/495057#M84465</link>
      <description>&lt;P&gt;This generally indicates that you have not adjusted the thruput setting on your HF from the default of 256kbs.&lt;BR /&gt;
My suggestion is to change/add the value in limits.conf to maxKBps=0, or a number greater than the default that you think your network can support. The forwarder is being throttled and cannot keep up with the data it's trying to send to the indexers.&lt;/P&gt;

&lt;P&gt;[thruput]&lt;BR /&gt;
maxKBps =   (0 = unlimited)&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/Limitsconf"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Admin/Limitsconf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2020 22:39:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Parsing-Queue-blocked-on-Heavy-Forwarder/m-p/495057#M84465</guid>
      <dc:creator>codebuilder</dc:creator>
      <dc:date>2020-03-16T22:39:28Z</dc:date>
    </item>
  </channel>
</rss>

