Getting Data In

Help on Splunk indexation suddenly stopped

jip31
Motivator

Hi

Since 2 dans, our index doesnt collect any events

The licence volume is OK

We have rebooted the Splunk indexer but the issue is the same 

I have heard about he MAX_EVENTS = 10000 limitation in props.conf

Does the issue can due to this limitation ?

If not, could you give some other traces to inspect?

Thanks in advance

 

Tags (1)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @jip31 ...Please provide us some more details..

1. may we know your daily license volume pls

2. indexer cluster or single indexer

3. did you/your team performed any change to config files or upgrades recently... any app's installed/upgraded recently?!?!

4. approx how many UF's are sending logs to this particular 2 indexes

5. can we know the details of these 2 indexes... is it custom app index or it default like linux, windows, etc..

MAX_EVENTS = <integer>
* The maximum number of input lines to add to any event.
* Splunk software breaks after it reads the specified number of lines.
* Default: 256

the max_events=10000 should not be an issue at all, i feel. 

Best Regards,
Sekar
my youtube channel for Splunk Newbie Learnings
https://www.youtube.com/@SiemNewbies101/videos

 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

jip31
Motivator

Hi

My answers below

 

1. may we know your daily license volume pls

We use approximativement 10% of the licence volume per day

2. indexer cluster or single indexer

Single indexer

3. did you/your team performed any change to config files or upgrades recently... any app's installed/upgraded recently?!?!

No

4. approx how many UF's are sending logs to this particular 2 indexes

Just one

5. can we know the details of these 2 indexes... is it custom app index or it default like linux, windows, etc..

We have syslog index and a Windows index

0 Karma

inventsekar
SplunkTrust
SplunkTrust

4. approx how many UF's are sending logs to this particular 2 indexes

Just one

 

ok then..
1) is the UF really generating the logs you are expecting (did you manually saw the logs availability at the UF?)

2) from the UF, are you receiving logs to other indexes(other than syslog and windows indexes) normally now?

3) did you try restarting splunk service at the UF?

 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...