<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Not receiving data in internal index in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/680602#M232629</link>
    <description>You could/should set MC also in single node. Just like in distributed environment.&lt;BR /&gt;The previous conf presentation shows you how to look those logs on OS level if those are not deliver into your splunk server.</description>
    <pubDate>Wed, 13 Mar 2024 21:21:56 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2024-03-13T21:21:56Z</dc:date>
    <item>
      <title>Not receiving data in internal index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/679141#M232162</link>
      <description>&lt;P&gt;From last two days I am not receiving data in my Splunk internal index.&amp;nbsp; Please help me understand this issue .&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1709221231323.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29558i3B8CC8EF3DF49BF0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1709221231323.png" alt="uagraw01_0-1709221231323.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 15:41:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/679141#M232162</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-02-29T15:41:26Z</dc:date>
    </item>
    <item>
      <title>Re: Not receiving data in internal index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/679146#M232165</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/70277"&gt;@uagraw01&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if, in the same period, you're receiving the other logs in the other not internal indexes, this means that you have a congestion of data and internal logs (having a minor priority) are skipper, check the queues in your Forwarders.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 15:53:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/679146#M232165</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-02-29T15:53:45Z</dc:date>
    </item>
    <item>
      <title>Re: Not receiving data in internal index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/679167#M232166</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;Yes we are receiving the data from other indexes in Splunk. We are not using any UF we are using Kafka and it sends data to different indexes.&amp;nbsp;&lt;BR /&gt;No no data in internal index creates any issue? Because I want to see internal logs for last 24 hours but nothing registered there.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 16:25:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/679167#M232166</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-02-29T16:25:51Z</dc:date>
    </item>
    <item>
      <title>Re: Not receiving data in internal index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/679168#M232167</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/70277"&gt;@uagraw01&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I didn't used Kafka, but when only internal indexes stop to arrive it's usually a queue issue.&lt;/P&gt;&lt;P&gt;Check your queues.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 16:28:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/679168#M232167</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-02-29T16:28:56Z</dc:date>
    </item>
    <item>
      <title>Re: Not receiving data in internal index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/679169#M232168</link>
      <description>Even you are using Kafka as a transport method, you should have your splunk infra’s internal logs there. What kind of setup yo have?</description>
      <pubDate>Thu, 29 Feb 2024 16:40:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/679169#M232168</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-02-29T16:40:22Z</dc:date>
    </item>
    <item>
      <title>Re: Not receiving data in internal index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/679171#M232169</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;Till to 27th we received all the internal index logs&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 16:46:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/679171#M232169</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-02-29T16:46:08Z</dc:date>
    </item>
    <item>
      <title>Re: Not receiving data in internal index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/679172#M232170</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;Queue issue from the Splunk side ??&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 16:48:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/679172#M232170</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-02-29T16:48:27Z</dc:date>
    </item>
    <item>
      <title>Re: Not receiving data in internal index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/679175#M232171</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/70277"&gt;@uagraw01&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;yes: I found many times that the stop in internal logs forwarding is usually caused by a queue issue from Splunk Side.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 16:51:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/679175#M232171</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-02-29T16:51:09Z</dc:date>
    </item>
    <item>
      <title>Re: Not receiving data in internal index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/679182#M232174</link>
      <description>Maybe this helps you to find blocking spot? &lt;A href="https://conf.splunk.com/files/2019/slides/FN1570.pdf" target="_blank"&gt;https://conf.splunk.com/files/2019/slides/FN1570.pdf&lt;/A&gt;</description>
      <pubDate>Thu, 29 Feb 2024 17:25:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/679182#M232174</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-02-29T17:25:07Z</dc:date>
    </item>
    <item>
      <title>Re: Not receiving data in internal index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/680586#M232624</link>
      <description>&lt;P&gt;We are using standalone Splunk server and their no monitoring console setup. Internal index logs are still not visible to me and without it, not able to troubleshoot further. Please help me what are the other workarounds are available to get the data in from internal indexes again.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2024 19:17:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/680586#M232624</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-03-13T19:17:57Z</dc:date>
    </item>
    <item>
      <title>Re: Not receiving data in internal index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/680602#M232629</link>
      <description>You could/should set MC also in single node. Just like in distributed environment.&lt;BR /&gt;The previous conf presentation shows you how to look those logs on OS level if those are not deliver into your splunk server.</description>
      <pubDate>Wed, 13 Mar 2024 21:21:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/680602#M232629</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-03-13T21:21:56Z</dc:date>
    </item>
    <item>
      <title>Re: Not receiving data in internal index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/680632#M232647</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;As per the PDF shared by you,. The below navigation data belongs to _internal index, and we are currently not getting any events from _internal index. Is there any approach in which I can enable the revive the _internal index data in Splunk.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1710391025769.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29741iAA7B54F612D36160/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1710391025769.png" alt="uagraw01_0-1710391025769.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 04:39:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/680632#M232647</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-03-14T04:39:16Z</dc:date>
    </item>
    <item>
      <title>Re: Not receiving data in internal index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/680641#M232650</link>
      <description>&lt;P&gt;You could look that same data from OS level from some of those log under $SPLUNK_HOME/var/log/splunk/&lt;BR /&gt;There are at least splunkd.log metrics.log etc. Those contains all same data as you have in _internal. Of course you must have shell level access to those all source hosts to see this.&lt;/P&gt;&lt;P&gt;You should just look couple of pages later where is said "Using "grep" cli command". In that and some pages after that is told/show how you can do it on command line with those log files like metrics.log.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 07:34:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/680641#M232650</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-03-14T07:34:05Z</dc:date>
    </item>
    <item>
      <title>Re: Not receiving data in internal index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/680643#M232651</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/70277"&gt;@uagraw01&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;yes, as I said, i experienced this issue in some Splunk installations when there was a queue congestion in Splunk Data Flow from the Forwarders to the Indexers.&lt;/P&gt;&lt;P&gt;In these cases, the _internal logs have a less priority than the other logs so they arrive late or they don't arrive.&lt;/P&gt;&lt;P&gt;You can check the queue on your forwarders using a simple search:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal  source=*metrics.log sourcetype=splunkd group=queue 
| eval name=case(name=="aggqueue","2 - Aggregation Queue",
 name=="indexqueue", "4 - Indexing Queue",
 name=="parsingqueue", "1 - Parsing Queue",
 name=="typingqueue", "3 - Typing Queue",
 name=="splunktcpin", "0 - TCP In Queue",
 name=="tcpin_cooked_pqueue", "0 - TCP In Queue") 
| eval max=if(isnotnull(max_size_kb),max_size_kb,max_size) 
| eval curr=if(isnotnull(current_size_kb),current_size_kb,current_size) 
| eval fill_perc=round((curr/max)*100,2) 
| bin _time span=1m
| stats Median(fill_perc) AS "fill_percentage" perc90(fill_perc) AS "90_perc" max(max) AS max max(curr) AS curr by host, _time, name 
| where (fill_percentage&amp;gt;70 AND name!="4 - Indexing Queue") OR (fill_percentage&amp;gt;70 AND name="4 - Indexing Queue")
| sort -_time&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 07:00:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/680643#M232651</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-03-14T07:00:28Z</dc:date>
    </item>
    <item>
      <title>Re: Not receiving data in internal index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/680651#M232654</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;How can execute your suggested search? It starts with index=_internal, and there is no data coming from that index.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 07:29:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/680651#M232654</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-03-14T07:29:37Z</dc:date>
    </item>
    <item>
      <title>Re: Not receiving data in internal index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/680654#M232655</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;The last event to come from the _internal index was on February 27, 2024, and below is the result of your search. I am pasting it below. Could you please help me understand the issue with the queue.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1710401873994.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29743i21424400B820AE1D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1710401873994.png" alt="uagraw01_0-1710401873994.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 07:39:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/680654#M232655</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-03-14T07:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: Not receiving data in internal index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/680724#M232665</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/70277"&gt;@uagraw01&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;the results mean that you have some queue but not so critical (you don't have 100%)&lt;/P&gt;&lt;P&gt;add to your search the host with missed logs and see if there are queues congestion on this host.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 17:00:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Not-receiving-data-in-internal-index/m-p/680724#M232665</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-03-14T17:00:41Z</dc:date>
    </item>
  </channel>
</rss>

