Getting Data In

Indexers outage - What can I do to troubleshoot?

GaetanVP
Contributor

Hello Splunkers, 

I am facing a problem with my indexers that are not able to index anymore. Neither the data forwarder to those indexers, neither the internal Splunk logs... I even tried to index data (simple txt file) directly from the indexer GUI, I do not get any error but my selected indexe will not be filled/updated.

Any clue what I can do to troubleshoot ? There is nothing in splunkd.log file, what other logs should I check?

Regards,
GaetanVP

Labels (1)
Tags (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @GaetanVP,

did you checked if you have sufficient disk space on indexers? usually this is the reason for stop internal indexing.

If you have sufficient disk space and resources, open a ticket to Splunk Support.

Ciao.

Giuseppe

GaetanVP
Contributor

Hello @gcusello, sorry for the late reply,

Just for information the problem was linked to a bad outputs.conf I put on my Indexers. As you know, having issues with outgoing traffic would impact the data flow in a way that tcpout queue would fill up, that was the case.

Thanks,

GaetanVP

Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...