Hi
Since 2 dans, our index doesnt collect any events
The licence volume is OK
We have rebooted the Splunk indexer but the issue is the same
I have heard about he MAX_EVENTS = 10000 limitation in props.conf
Does the issue can due to this limitation ?
If not, could you give some other traces to inspect?
Thanks in advance
Hi @jip31 ...Please provide us some more details..
1. may we know your daily license volume pls
2. indexer cluster or single indexer
3. did you/your team performed any change to config files or upgrades recently... any app's installed/upgraded recently?!?!
4. approx how many UF's are sending logs to this particular 2 indexes
5. can we know the details of these 2 indexes... is it custom app index or it default like linux, windows, etc..
MAX_EVENTS = <integer> * The maximum number of input lines to add to any event. * Splunk software breaks after it reads the specified number of lines. * Default: 256
the max_events=10000 should not be an issue at all, i feel.
Best Regards,
Sekar
my youtube channel for Splunk Newbie Learnings
https://www.youtube.com/@SiemNewbies101/videos
Hi
My answers below
1. may we know your daily license volume pls
We use approximativement 10% of the licence volume per day
2. indexer cluster or single indexer
Single indexer
3. did you/your team performed any change to config files or upgrades recently... any app's installed/upgraded recently?!?!
No
4. approx how many UF's are sending logs to this particular 2 indexes
Just one
5. can we know the details of these 2 indexes... is it custom app index or it default like linux, windows, etc..
We have syslog index and a Windows index
4. approx how many UF's are sending logs to this particular 2 indexes
Just one
ok then..
1) is the UF really generating the logs you are expecting (did you manually saw the logs availability at the UF?)
2) from the UF, are you receiving logs to other indexes(other than syslog and windows indexes) normally now?
3) did you try restarting splunk service at the UF?