Hello everyone,
I found due DMC console, that splunk stopped get logs into _introspection index.
I open search like this "index=_introspection sourcetype=splunk_resource_usage component=PerProcess host=*" and see that there were events, but they stopped.
Can anybody help me with this problem?
 
					
				
		
 
		
		
		
		
		
	
			
		
		
			
					
		There should be a message in splunkd.log explaining the problem.
index=_internal source=*splunkd.logCheck that there is enough storage on the volume containing the introspection index.
Also, confirm no one turned off introspection. See https://docs.splunk.com/Documentation/Splunk/8.2.2/Troubleshooting/ConfigurePIF#Disable_logging
the host is up
