<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: indexer peers and indexer clustering problem in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/indexer-peers-and-indexer-clustering-problem/m-p/699103#M10409</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/266570"&gt;@KhalidAlharthi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;if you have enough disk space the issue could be related to the resources of the Indexers:&amp;nbsp;&lt;/P&gt;&lt;P&gt;have you performant disks on your Indexers?&lt;/P&gt;&lt;P&gt;Splunk requires at least 800 IOPS (better 1200 or more!), and this is the bottleneck of each Splunk installation.&lt;/P&gt;&lt;P&gt;If you are using a shared virtual infrastructure, are the resources of the Splunk servers dedicated to them or shared?&lt;/P&gt;&lt;P&gt;They must be dedicated not shared.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Sun, 15 Sep 2024 08:21:02 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2024-09-15T08:21:02Z</dc:date>
    <item>
      <title>indexer peers and indexer clustering problem</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/indexer-peers-and-indexer-clustering-problem/m-p/698749#M10391</link>
      <description>&lt;P&gt;Hello Members,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have problems between the peers and managing node (CM), I tried to identify the issue but i canno't find a possible way to fix it because i didn't notice any problems regarding the connectivity&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;see the pic below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KhalidAlharthi_0-1726045838064.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32616iE8820A9A5EF19997/image-size/medium?v=v2&amp;amp;px=400" role="button" title="KhalidAlharthi_0-1726045838064.png" alt="KhalidAlharthi_0-1726045838064.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KhalidAlharthi_1-1726045885243.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32617iE3676FCF7A1CDAC6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="KhalidAlharthi_1-1726045885243.png" alt="KhalidAlharthi_1-1726045885243.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 09:12:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/indexer-peers-and-indexer-clustering-problem/m-p/698749#M10391</guid>
      <dc:creator>KhalidAlharthi</dc:creator>
      <dc:date>2024-09-11T09:12:07Z</dc:date>
    </item>
    <item>
      <title>Re: indexer peers and indexer clustering problem</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/indexer-peers-and-indexer-clustering-problem/m-p/698757#M10393</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/266570"&gt;@KhalidAlharthi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;the indexing queue is full, probably because you don't have enough disk space or there are too data for the resources Indexers have.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 09:46:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/indexer-peers-and-indexer-clustering-problem/m-p/698757#M10393</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-09-11T09:46:07Z</dc:date>
    </item>
    <item>
      <title>Re: indexer peers and indexer clustering problem</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/indexer-peers-and-indexer-clustering-problem/m-p/698758#M10394</link>
      <description>&lt;P&gt;how can i solve it the disk volume high but how can i ensure the data can be aligned is there commands or something to check ?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 09:56:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/indexer-peers-and-indexer-clustering-problem/m-p/698758#M10394</guid>
      <dc:creator>KhalidAlharthi</dc:creator>
      <dc:date>2024-09-11T09:56:53Z</dc:date>
    </item>
    <item>
      <title>Re: indexer peers and indexer clustering problem</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/indexer-peers-and-indexer-clustering-problem/m-p/698761#M10395</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/266570"&gt;@KhalidAlharthi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;when you'll give sufficient disk space, indexers should be automatically aligned, even if some time will be required.&lt;/P&gt;&lt;P&gt;You could check the replication status, after some time from the Cluster Master.&lt;/P&gt;&lt;P&gt;Cluster Master gives you the feature to force rebalancing.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 11:04:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/indexer-peers-and-indexer-clustering-problem/m-p/698761#M10395</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-09-11T11:04:43Z</dc:date>
    </item>
    <item>
      <title>Re: indexer peers and indexer clustering problem</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/indexer-peers-and-indexer-clustering-problem/m-p/699098#M10408</link>
      <description>&lt;P&gt;i have checked the main partitions of the system and hot/cold/frozen partition they have enough space and i think it's not the issue...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Sep 2024 06:53:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/indexer-peers-and-indexer-clustering-problem/m-p/699098#M10408</guid>
      <dc:creator>KhalidAlharthi</dc:creator>
      <dc:date>2024-09-15T06:53:31Z</dc:date>
    </item>
    <item>
      <title>Re: indexer peers and indexer clustering problem</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/indexer-peers-and-indexer-clustering-problem/m-p/699103#M10409</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/266570"&gt;@KhalidAlharthi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;if you have enough disk space the issue could be related to the resources of the Indexers:&amp;nbsp;&lt;/P&gt;&lt;P&gt;have you performant disks on your Indexers?&lt;/P&gt;&lt;P&gt;Splunk requires at least 800 IOPS (better 1200 or more!), and this is the bottleneck of each Splunk installation.&lt;/P&gt;&lt;P&gt;If you are using a shared virtual infrastructure, are the resources of the Splunk servers dedicated to them or shared?&lt;/P&gt;&lt;P&gt;They must be dedicated not shared.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sun, 15 Sep 2024 08:21:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/indexer-peers-and-indexer-clustering-problem/m-p/699103#M10409</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-09-15T08:21:02Z</dc:date>
    </item>
    <item>
      <title>Re: indexer peers and indexer clustering problem</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/indexer-peers-and-indexer-clustering-problem/m-p/699104#M10410</link>
      <description>&lt;P&gt;thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp; for responding,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i didn't miss up with disk storage or add any additional partitions .. last week i performed a new index from the CM and push it through indexers ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;about IOPS i don't know how can i check that using splunk&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for the virtual infrastructure splunk has it's own configuration and not shared with other resources ... (Vsphere)&lt;/P&gt;</description>
      <pubDate>Sun, 15 Sep 2024 09:51:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/indexer-peers-and-indexer-clustering-problem/m-p/699104#M10410</guid>
      <dc:creator>KhalidAlharthi</dc:creator>
      <dc:date>2024-09-15T09:51:12Z</dc:date>
    </item>
    <item>
      <title>Re: indexer peers and indexer clustering problem</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/indexer-peers-and-indexer-clustering-problem/m-p/699105#M10411</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/266570"&gt;@KhalidAlharthi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;you can check IOPS using an external tool as Bonnie++ or others.&lt;/P&gt;&lt;P&gt;Abour resource sharing,&amp;nbsp; it is a configuration in VM-Ware, even if these machines are only for Splunk but they are in a VM-Ware infrastructure where there are other VMs, it's required by Splunk that they must be dedicated (&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.3.0/Capacity/Referencehardware#Virtualized_Infrastructures" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.3.0/Capacity/Referencehardware#Virtualized_Infrastructures&lt;/A&gt;&amp;nbsp;).&lt;/P&gt;&lt;P&gt;Anyway, probably the issue is in the performaces of your virtual storage.&lt;/P&gt;&lt;P&gt;Then how many logs (daily average) are you indexing?&lt;/P&gt;&lt;P&gt;How many Indexers are you using and how many CPUs are there in each Indexer?&lt;/P&gt;&lt;P&gt;Splunk requires at least 12 CPUs for each Indexer and more if there's ES or ITSI, then you can index max 200 GB/day with one indexer (less if you have ES or ITSI), so it's relevant how many logs are you indexing.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sun, 15 Sep 2024 10:09:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/indexer-peers-and-indexer-clustering-problem/m-p/699105#M10411</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-09-15T10:09:48Z</dc:date>
    </item>
    <item>
      <title>Re: indexer peers and indexer clustering problem</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/indexer-peers-and-indexer-clustering-problem/m-p/699107#M10412</link>
      <description>&lt;P&gt;for today this is the volume used&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KhalidAlharthi_0-1726395756770.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32644i9C9D18AECDB7360B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="KhalidAlharthi_0-1726395756770.png" alt="KhalidAlharthi_0-1726395756770.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;there are 3 indexers each one of them has 16 CPU's&lt;/P&gt;</description>
      <pubDate>Sun, 15 Sep 2024 10:23:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/indexer-peers-and-indexer-clustering-problem/m-p/699107#M10412</guid>
      <dc:creator>KhalidAlharthi</dc:creator>
      <dc:date>2024-09-15T10:23:25Z</dc:date>
    </item>
    <item>
      <title>Re: indexer peers and indexer clustering problem</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/indexer-peers-and-indexer-clustering-problem/m-p/699154#M10413</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/266570"&gt;@KhalidAlharthi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;ok, it shouldn't be a resource issue .&lt;/P&gt;&lt;P&gt;The only possibility is the throughput of the disks, that you can check only with an external tool like Bonnie++.&lt;/P&gt;&lt;P&gt;Could you check the resources of your indexers using the Monitoring Console?&lt;/P&gt;&lt;P&gt;Please check if the resources are fully used.&lt;/P&gt;&lt;P&gt;Then, you could try to configure the parallel pipeline on your indexers, for more infos see at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.3.0/Indexer/Pipelinesets" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.3.0/Indexer/Pipelinesets&lt;/A&gt;&lt;/P&gt;&lt;P&gt;you could try to use the value&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;parallelIngestionPipelines = 2&lt;/LI-CODE&gt;&lt;P&gt;in the General stanza of server.conf, in this way you better use your hardware resources.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 16 Sep 2024 05:43:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/indexer-peers-and-indexer-clustering-problem/m-p/699154#M10413</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-09-16T05:43:16Z</dc:date>
    </item>
    <item>
      <title>Re: indexer peers and indexer clustering problem</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/indexer-peers-and-indexer-clustering-problem/m-p/699189#M10414</link>
      <description>&lt;P&gt;Load the Monitoring Console&lt;/P&gt;&lt;P&gt;Indexing -&amp;gt; Performance -&amp;gt; Indexing Performance: Instance&lt;/P&gt;&lt;P&gt;Select various Indexers in your cluster to compare&lt;/P&gt;&lt;P&gt;- If various Indexers have massively different queue values then you may have a data imbalance, since UF's by default stick to an ingestion queue for 30 seconds you should observe this over time.&lt;/P&gt;&lt;P&gt;- If all queues left to the right are full then this is a disk write issue, the indexer can't write to disk fast enough.&lt;/P&gt;&lt;P&gt;- You can via .conf settings override default indexer queue and pipeline settings to increase available size, but you should be very confident in your admin abilities and I don't recommend this for novice administrators.&amp;nbsp; Working with Splunk support is recommended regardless of your experience novice or advanced.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Sep 2024 14:22:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/indexer-peers-and-indexer-clustering-problem/m-p/699189#M10414</guid>
      <dc:creator>dural_yyz</dc:creator>
      <dc:date>2024-09-16T14:22:37Z</dc:date>
    </item>
  </channel>
</rss>

