Getting Data In

How Indexers behave when it comes into detention state ?

tsawa_splunk
Splunk Employee
Splunk Employee

I understand Splunk provides multiple means to control the disk size for indexing, and I want to understand better around minFreeSpace option which is specified in server.conf.

If the actual usage of the filesystem exceeds the threshold specified by minFreeSpace, how will the data which was seized from being indexed be handled after the disk space gets freed ? As long as the ack on Forwarder is enabled, will the data again be collected and indexed, or will it be just lost ?

I assume the result may be varied across types of input, forwarder, tcp/udp, HEC, etc ...
Any detailed answer would be highly appreciated.

0 Karma
1 Solution

FrankVl
Ultra Champion

If an indexer goes into detention, it will stop accepting new data on its inputs. If you have multiple indexers and you've set up your forwarders to load balance across your indexers, they will simply divert to the other indexers. If you have only a single indexer, then queues will start filling up on your forwarders and once those are full, their inputs will also block. In some cases your data sources may cache and resend once the blockage is over, but in many cases data will start to get lost (especially with 'unreliable' transport methods like UDP).

View solution in original post

FrankVl
Ultra Champion

If an indexer goes into detention, it will stop accepting new data on its inputs. If you have multiple indexers and you've set up your forwarders to load balance across your indexers, they will simply divert to the other indexers. If you have only a single indexer, then queues will start filling up on your forwarders and once those are full, their inputs will also block. In some cases your data sources may cache and resend once the blockage is over, but in many cases data will start to get lost (especially with 'unreliable' transport methods like UDP).

Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...