Getting Data In

Help on Splunk indexation suddenly stopped

jip31
Motivator

Hi

Since 2 dans, our index doesnt collect any events

The licence volume is OK

We have rebooted the Splunk indexer but the issue is the same 

I have heard about he MAX_EVENTS = 10000 limitation in props.conf

Does the issue can due to this limitation ?

If not, could you give some other traces to inspect?

Thanks in advance

 

Tags (1)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @jip31 ...Please provide us some more details..

1. may we know your daily license volume pls

2. indexer cluster or single indexer

3. did you/your team performed any change to config files or upgrades recently... any app's installed/upgraded recently?!?!

4. approx how many UF's are sending logs to this particular 2 indexes

5. can we know the details of these 2 indexes... is it custom app index or it default like linux, windows, etc..

MAX_EVENTS = <integer>
* The maximum number of input lines to add to any event.
* Splunk software breaks after it reads the specified number of lines.
* Default: 256

the max_events=10000 should not be an issue at all, i feel. 

Best Regards,
Sekar
my youtube channel for Splunk Newbie Learnings
https://www.youtube.com/@SiemNewbies101/videos

 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

jip31
Motivator

Hi

My answers below

 

1. may we know your daily license volume pls

We use approximativement 10% of the licence volume per day

2. indexer cluster or single indexer

Single indexer

3. did you/your team performed any change to config files or upgrades recently... any app's installed/upgraded recently?!?!

No

4. approx how many UF's are sending logs to this particular 2 indexes

Just one

5. can we know the details of these 2 indexes... is it custom app index or it default like linux, windows, etc..

We have syslog index and a Windows index

0 Karma

inventsekar
SplunkTrust
SplunkTrust

4. approx how many UF's are sending logs to this particular 2 indexes

Just one

 

ok then..
1) is the UF really generating the logs you are expecting (did you manually saw the logs availability at the UF?)

2) from the UF, are you receiving logs to other indexes(other than syslog and windows indexes) normally now?

3) did you try restarting splunk service at the UF?

 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...