Getting Data In

Indexers outage - What can I do to troubleshoot?

GaetanVP
Contributor

Hello Splunkers, 

I am facing a problem with my indexers that are not able to index anymore. Neither the data forwarder to those indexers, neither the internal Splunk logs... I even tried to index data (simple txt file) directly from the indexer GUI, I do not get any error but my selected indexe will not be filled/updated.

Any clue what I can do to troubleshoot ? There is nothing in splunkd.log file, what other logs should I check?

Regards,
GaetanVP

Labels (1)
Tags (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @GaetanVP,

did you checked if you have sufficient disk space on indexers? usually this is the reason for stop internal indexing.

If you have sufficient disk space and resources, open a ticket to Splunk Support.

Ciao.

Giuseppe

GaetanVP
Contributor

Hello @gcusello, sorry for the late reply,

Just for information the problem was linked to a bad outputs.conf I put on my Indexers. As you know, having issues with outgoing traffic would impact the data flow in a way that tcpout queue would fill up, that was the case.

Thanks,

GaetanVP

Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...