Getting Data In

Help on Splunk indexation suddenly stopped

jip31
Motivator

Hi

Since 2 dans, our index doesnt collect any events

The licence volume is OK

We have rebooted the Splunk indexer but the issue is the same 

I have heard about he MAX_EVENTS = 10000 limitation in props.conf

Does the issue can due to this limitation ?

If not, could you give some other traces to inspect?

Thanks in advance

 

Tags (1)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @jip31 ...Please provide us some more details..

1. may we know your daily license volume pls

2. indexer cluster or single indexer

3. did you/your team performed any change to config files or upgrades recently... any app's installed/upgraded recently?!?!

4. approx how many UF's are sending logs to this particular 2 indexes

5. can we know the details of these 2 indexes... is it custom app index or it default like linux, windows, etc..

MAX_EVENTS = <integer>
* The maximum number of input lines to add to any event.
* Splunk software breaks after it reads the specified number of lines.
* Default: 256

the max_events=10000 should not be an issue at all, i feel. 

Best Regards,
Sekar
my youtube channel for Splunk Newbie Learnings
https://www.youtube.com/@SiemNewbies101/videos

 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

jip31
Motivator

Hi

My answers below

 

1. may we know your daily license volume pls

We use approximativement 10% of the licence volume per day

2. indexer cluster or single indexer

Single indexer

3. did you/your team performed any change to config files or upgrades recently... any app's installed/upgraded recently?!?!

No

4. approx how many UF's are sending logs to this particular 2 indexes

Just one

5. can we know the details of these 2 indexes... is it custom app index or it default like linux, windows, etc..

We have syslog index and a Windows index

0 Karma

inventsekar
SplunkTrust
SplunkTrust

4. approx how many UF's are sending logs to this particular 2 indexes

Just one

 

ok then..
1) is the UF really generating the logs you are expecting (did you manually saw the logs availability at the UF?)

2) from the UF, are you receiving logs to other indexes(other than syslog and windows indexes) normally now?

3) did you try restarting splunk service at the UF?

 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...