All Apps and Add-ons

Subscription Status - Unacknowledged Messages on Pub/Sub [Google Cloud Platform Add-on]

mikaelarz45
Explorer

Hi everyone,

I would like to ask some help regarding the alerts we are getting in Google Stackdriver. This is regarding the unacknowledged messages in our environment. We still don't know why there are so many unacknowledged messages for this add-on.

Please see image below.

alt text

How to resolve this issue of unacknowledged messages? Note: The add-on is placed on the heavy forwarder.

0 Karma
1 Solution

mikaelarz45
Explorer

Issue has been resolved.

Note: This issue is happening since the input cannot cope up with the large number of messages.

To fix this, just clone your existing inputs that is is supposedly getting this messages.

The answer we have been looking for is under the troubleshooting guide of the app.
https://docs.splunk.com/Documentation/AddOns/released/GoogleCloud/Troubleshoot

View solution in original post

0 Karma

mikaelarz45
Explorer

Issue has been resolved.

Note: This issue is happening since the input cannot cope up with the large number of messages.

To fix this, just clone your existing inputs that is is supposedly getting this messages.

The answer we have been looking for is under the troubleshooting guide of the app.
https://docs.splunk.com/Documentation/AddOns/released/GoogleCloud/Troubleshoot

0 Karma

tyron_
Explorer

So you will end up with multiple inputs, but on the backend using the same subscription. Is that correct?
I believe that would be the only way to avoid duplicate messages, right? If you have multiple subscriptions as well, you will get duplicates

0 Karma

mikaelarz45
Explorer

Yes that's correct.

0 Karma

vik_splunk
Communicator

@mikaelarz45 . Thanks much. Will give this a try. Appreciate it!

0 Karma

vik_splunk
Communicator

I know i am a bit late to the party but was this resolved @mikaelarz45 ??

We are facing the exact same issue now

0 Karma

mikaelarz45
Explorer

Hi @vik_splunk, this was resolved on our end. I've forgotten about this question and failed to post the solution. But here is what we did to resolve this.

Note: This issue is happening since the input cannot cope up with the large number of messages.

To fix this, just clone your existing inputs that is is supposedly getting this messages.

The answer we have been looking for is under the troubleshooting guide of the app.
https://docs.splunk.com/Documentation/AddOns/released/GoogleCloud/Troubleshoot

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...