Getting Data In

Daily indexing volume limit exceeded shown on forwarder

remy06
Contributor

Hi,

I have installed Splunk on serverA. ServerA is configured to monitor local events and at the same time is pulling WMI events from serverB.

It is configured as a regular forwarder and is forwarding both events to our Splunk indexer.

When I login to Splunkweb at ServerA,I get a notice bar at the top of the page stating "Daily indexing volume limit exceeded".

Is there any concern for this as it is already configured as a forwarder? Will it have any effect on the events being indexed?

Tags (3)
0 Karma

remy06
Contributor

splunk 4.1.5. Have configured it as a forwarder so should be using the forwarder license.

0 Karma

araitz
Splunk Employee
Splunk Employee

You never stated what version of Splunk this is, or what license you are using.

0 Karma

bwooden
Splunk Employee
Splunk Employee

It will not affect indexing but you may wish to resolve it so you don't become immune to noticing error messages.  🙂

Verify the forwarder is not indexing AND forwarding.

From the GUI, you would follow these steps...

   1. click Manager > Forwarding and receiving > Forwarding defualts
   2. Select radio button "No" for "Store a local copy of forwarded events?"
   3. click Save button

This is equivalent to outputs.conf setting:

indexAndForward = false
0 Karma

remy06
Contributor

It seems to be still performing its task..but the notice is still there..Anyone?

0 Karma

remy06
Contributor

It is already configured not to "store a local copy of forwarded events".

This serverA is used to pull WMI events from serverB which filters off some windows events and the forwards them to Splunk indexer. It is at the same time forwarding local events to Splunk indexer.In this case is it indexing and forwarding as well?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...