Dashboards & Visualizations

Splunk HEC Token Log ingestion slowness

ram254481493
Explorer

i am using HEC tokens to collect the logs from servers. Sometimes we are firing the events but the events is not coming to splunk. We have one indexer and our all tokens are managed on the indexer only. The moment we restart the indexer , all the logs will comes up frequently. If we dont restart we are not getting logs sending from HEC Tokens ?

what is the issue , how can i fix it ? why most of the time only a restart is pulling the logs ?

Tags (1)
0 Karma
1 Solution

tiagofbmm
Influencer

I'd check the monitoring console for queues getting filled up on your indexers. When you restart, they get cleaned up so maybe that's a reason for it.

Check queue fill ratio in Indexer Performance of Monitoring Console

View solution in original post

0 Karma

tiagofbmm
Influencer

I'd check the monitoring console for queues getting filled up on your indexers. When you restart, they get cleaned up so maybe that's a reason for it.

Check queue fill ratio in Indexer Performance of Monitoring Console

0 Karma

ram254481493
Explorer

Now i checked i saw everything in 0 their , do i need to check when the issue comes again , and if its the case how can i clear those ?

0 Karma

tiagofbmm
Influencer

You can't clear the queues. They are there to avoid a total Splunk crash and serve as a buffer that will get filled and emptied according to data flow rate and processing capacity. If you see that queues are full when you stop receiving events or are receiving too few events, then it is time for evaluation.

Maybe you have not adequate machines to ingest that amount of data, but I'm purely speculating. Check the indicators in the queues, and resource in general for your indexer layer to see if it is overflowing.

0 Karma

ram254481493
Explorer

ok got it apart from it is their any other issues where we will point out the delay ?

0 Karma

tiagofbmm
Influencer

I'd say it has to be resource consumption, either queues filling up, RAM or CPUs, or even your network not coping with the volume, all that can be analyzed in the Monitoring Console

0 Karma

ram254481493
Explorer

Hi tiago , i checked again the issue came , the quefill ratio everything looks good but dont know why logging sometimes stopped then after restart of the indexer all stucked logs came is it due to less logging volume ?

0 Karma

ram254481493
Explorer

ok thanks tiago i will monitor when net time this issue will comes up.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...