Deployment Architecture

Data acceleration lead to indexer down

wilfredluiz
New Member

Hi Community

My indexer stopped indexing data after I tried accelerating 7+ data models for CIM.

Since I'm working remotely I'm unable to reach the search head GUI (server not reachable).  Please help me fix this issue.

 

Thanks!

Labels (3)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @wilfredluiz,

About the Data Model Acceleration, you should check the system resources (both on Indexers and Search Heads) using the Splunk Monitor Console and see if there's some problem.

About the question how to reach the SH, you should be able to reach it by SSH to see if Splunk is up and running.

Eventually you can disable some or all the acceleration by conf files, if this is the problem.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...