<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Logs stopped from one of the server in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Logs-stopped-from-one-of-the-server/m-p/537784#M90123</link>
    <description>&lt;P&gt;Hi Splunkers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am facing a strange issue like the splunk forwarder stopped forwarding data. I see the forwarder is working fine and as per the splunk logs I see&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;The&lt;/SPAN&gt; &lt;SPAN class="t"&gt;monitor&lt;/SPAN&gt; &lt;SPAN class="t"&gt;input&lt;/SPAN&gt; &lt;SPAN class="t"&gt;cannot&lt;/SPAN&gt; &lt;SPAN class="t"&gt;produce&lt;/SPAN&gt; &lt;SPAN class="t"&gt;data&lt;/SPAN&gt; &lt;SPAN class="t"&gt;because&lt;/SPAN&gt; &lt;SPAN class="t"&gt;splunkd&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;s&lt;/SPAN&gt; &lt;SPAN class="t"&gt;processing&lt;/SPAN&gt; &lt;SPAN class="t"&gt;queues&lt;/SPAN&gt; &lt;SPAN class="t"&gt;are&lt;/SPAN&gt; &lt;SPAN class="t"&gt;full.&lt;/SPAN&gt; &lt;SPAN class="t"&gt;This&lt;/SPAN&gt; &lt;SPAN class="t"&gt;will&lt;/SPAN&gt; &lt;SPAN class="t"&gt;be&lt;/SPAN&gt; &lt;SPAN class="t"&gt;caused&lt;/SPAN&gt; &lt;SPAN class="t"&gt;by&lt;/SPAN&gt; &lt;SPAN class="t"&gt;inadequate&lt;/SPAN&gt; &lt;SPAN class="t"&gt;indexing&lt;/SPAN&gt; &lt;SPAN class="t"&gt;or&lt;/SPAN&gt; &lt;SPAN class="t"&gt;forwarding&lt;/SPAN&gt; &lt;SPAN class="t"&gt;rate&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;or&lt;/SPAN&gt; &lt;SPAN class="t"&gt;a&lt;/SPAN&gt; &lt;SPAN class="t"&gt;sudden&lt;/SPAN&gt; &lt;SPAN class="t"&gt;burst&lt;/SPAN&gt; &lt;SPAN class="t"&gt;of&lt;/SPAN&gt; &lt;SPAN class="t"&gt;incoming&lt;/SPAN&gt; &lt;SPAN class="t"&gt;data&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;I tried restarting the indexers and forwarder. It works for a while and after that it stops.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Could you please advice.&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Amit&lt;/P&gt;</description>
    <pubDate>Fri, 29 Jan 2021 04:38:14 GMT</pubDate>
    <dc:creator>asharmaeqfx</dc:creator>
    <dc:date>2021-01-29T04:38:14Z</dc:date>
    <item>
      <title>Logs stopped from one of the server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-stopped-from-one-of-the-server/m-p/537784#M90123</link>
      <description>&lt;P&gt;Hi Splunkers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am facing a strange issue like the splunk forwarder stopped forwarding data. I see the forwarder is working fine and as per the splunk logs I see&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;The&lt;/SPAN&gt; &lt;SPAN class="t"&gt;monitor&lt;/SPAN&gt; &lt;SPAN class="t"&gt;input&lt;/SPAN&gt; &lt;SPAN class="t"&gt;cannot&lt;/SPAN&gt; &lt;SPAN class="t"&gt;produce&lt;/SPAN&gt; &lt;SPAN class="t"&gt;data&lt;/SPAN&gt; &lt;SPAN class="t"&gt;because&lt;/SPAN&gt; &lt;SPAN class="t"&gt;splunkd&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;s&lt;/SPAN&gt; &lt;SPAN class="t"&gt;processing&lt;/SPAN&gt; &lt;SPAN class="t"&gt;queues&lt;/SPAN&gt; &lt;SPAN class="t"&gt;are&lt;/SPAN&gt; &lt;SPAN class="t"&gt;full.&lt;/SPAN&gt; &lt;SPAN class="t"&gt;This&lt;/SPAN&gt; &lt;SPAN class="t"&gt;will&lt;/SPAN&gt; &lt;SPAN class="t"&gt;be&lt;/SPAN&gt; &lt;SPAN class="t"&gt;caused&lt;/SPAN&gt; &lt;SPAN class="t"&gt;by&lt;/SPAN&gt; &lt;SPAN class="t"&gt;inadequate&lt;/SPAN&gt; &lt;SPAN class="t"&gt;indexing&lt;/SPAN&gt; &lt;SPAN class="t"&gt;or&lt;/SPAN&gt; &lt;SPAN class="t"&gt;forwarding&lt;/SPAN&gt; &lt;SPAN class="t"&gt;rate&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;or&lt;/SPAN&gt; &lt;SPAN class="t"&gt;a&lt;/SPAN&gt; &lt;SPAN class="t"&gt;sudden&lt;/SPAN&gt; &lt;SPAN class="t"&gt;burst&lt;/SPAN&gt; &lt;SPAN class="t"&gt;of&lt;/SPAN&gt; &lt;SPAN class="t"&gt;incoming&lt;/SPAN&gt; &lt;SPAN class="t"&gt;data&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;I tried restarting the indexers and forwarder. It works for a while and after that it stops.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Could you please advice.&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Amit&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 04:38:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-stopped-from-one-of-the-server/m-p/537784#M90123</guid>
      <dc:creator>asharmaeqfx</dc:creator>
      <dc:date>2021-01-29T04:38:14Z</dc:date>
    </item>
    <item>
      <title>Re: Logs stopped from one of the server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-stopped-from-one-of-the-server/m-p/537786#M90124</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;check the following&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. check your splunk forwarder &lt;STRONG&gt;version&lt;/STRONG&gt; in server&lt;/P&gt;&lt;P&gt;2. check if &lt;STRONG&gt;firewall&lt;/STRONG&gt; opened for the server&lt;/P&gt;&lt;P&gt;3. check the sever record in splunk forwarder management(splunk web-settings-&lt;STRONG&gt;forwarder management&lt;/STRONG&gt;)&lt;/P&gt;&lt;P&gt;4. if splunk forwarder service is stopped in server. Please restart the service by running &lt;STRONG&gt;services.msc&lt;/STRONG&gt; in command prompt&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it will help you.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 05:30:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-stopped-from-one-of-the-server/m-p/537786#M90124</guid>
      <dc:creator>vamshiangothu</dc:creator>
      <dc:date>2021-01-29T05:30:34Z</dc:date>
    </item>
    <item>
      <title>Re: Logs stopped from one of the server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-stopped-from-one-of-the-server/m-p/537794#M90127</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/46853"&gt;@asharmaeqfx&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You can search in indexer's internal log for "The index processor has paused data flow". This log will show you the reason why it does not accept data. It may be a free disk space problem too.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 05:52:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-stopped-from-one-of-the-server/m-p/537794#M90127</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-01-29T05:52:53Z</dc:date>
    </item>
    <item>
      <title>Re: Logs stopped from one of the server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logs-stopped-from-one-of-the-server/m-p/538018#M90181</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your kind replies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have to delete some big logs and after that restarted the Splunk forwarder. It has been working since Friday.&lt;/P&gt;&lt;P&gt;As per your suggestion i think it was because the amount of logs which were being forwarded seems to be quite big and did not allow it to be forwarder and queues were getting full.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Amit&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 00:53:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logs-stopped-from-one-of-the-server/m-p/538018#M90181</guid>
      <dc:creator>asharmaeqfx</dc:creator>
      <dc:date>2021-02-01T00:53:43Z</dc:date>
    </item>
  </channel>
</rss>

