Getting Data In

Help on Splunk indexation suddenly stopped

jip31
Motivator

Hi

Since 2 dans, our index doesnt collect any events

The licence volume is OK

We have rebooted the Splunk indexer but the issue is the same 

I have heard about he MAX_EVENTS = 10000 limitation in props.conf

Does the issue can due to this limitation ?

If not, could you give some other traces to inspect?

Thanks in advance

 

Tags (1)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @jip31 ...Please provide us some more details..

1. may we know your daily license volume pls

2. indexer cluster or single indexer

3. did you/your team performed any change to config files or upgrades recently... any app's installed/upgraded recently?!?!

4. approx how many UF's are sending logs to this particular 2 indexes

5. can we know the details of these 2 indexes... is it custom app index or it default like linux, windows, etc..

MAX_EVENTS = <integer>
* The maximum number of input lines to add to any event.
* Splunk software breaks after it reads the specified number of lines.
* Default: 256

the max_events=10000 should not be an issue at all, i feel. 

Best Regards,
Sekar
my youtube channel for Splunk Newbie Learnings
https://www.youtube.com/@SiemNewbies101/videos

 

0 Karma

jip31
Motivator

Hi

My answers below

 

1. may we know your daily license volume pls

We use approximativement 10% of the licence volume per day

2. indexer cluster or single indexer

Single indexer

3. did you/your team performed any change to config files or upgrades recently... any app's installed/upgraded recently?!?!

No

4. approx how many UF's are sending logs to this particular 2 indexes

Just one

5. can we know the details of these 2 indexes... is it custom app index or it default like linux, windows, etc..

We have syslog index and a Windows index

0 Karma

inventsekar
SplunkTrust
SplunkTrust

4. approx how many UF's are sending logs to this particular 2 indexes

Just one

 

ok then..
1) is the UF really generating the logs you are expecting (did you manually saw the logs availability at the UF?)

2) from the UF, are you receiving logs to other indexes(other than syslog and windows indexes) normally now?

3) did you try restarting splunk service at the UF?

 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...