I have following in the logs-
INFO TailReader - Could not send data to output queue (parsingQueue), retrying... INFO TailReader - ...continuing.
On checking the metrics.log, I can see it reads-
INFO Metrics - group=queue, name=parsingqueue, blocked=true, max_size_kb=512, current_size_kb=511
So, the problem is likely on the indexing side only - perhaps the indexing box is overloaded.
Any idea what can be done to fix this?
Sorry for the late reply. The server indeed monitors huge number of log files.
I increased the maxSize limit to a higher value in server.conf at the location ...\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\default\ and it helped.