Getting Data In

Kafka Broker Error – Topics not receiving events (Status code KAFKA-1)

kn450
Explorer

Hello,

I’m experiencing an issue with my Kafka broker integration with Splunk.
The error message I’m seeing is:

Kafka Broker Error
Topic bytes in
The rate, expressed in bytes per second, of the message traffic each topic is receiving from producing clients

Error:
Kafka topics are not receiving events.
Monitor for an hour, if the status does not go back to OK, restart kafka-server. 
If this does not help, contact Splunk Support.
Status code KAFKA-1

I have monitored for more than an hour, and the status did not return to OK.
Has anyone faced this issue before or have suggestions on how to fix it?

Thanks in advance!

Labels (1)
0 Karma

PrewinThomas
Motivator

@kn450 

Did you restart kafka-server?

Also have a look at this,
#https://splunk.my.site.com/customer/s/article/KAFKA-1-and-OML-2-errors

Regards,
Prewin
If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

0 Karma

kn450
Explorer

 

Hi Prewin,

I restarted the Kafka server as suggested, but the issue persists. The Kafka broker is not receiving any events on the topics. Here is the error message I see in the dashboard:

Kafka topics are not receiving events.
Monitor for an hour, if the status does not go back to OK, restart kafka-server. If this does not help, contact Splunk Support.
Status code KAFKA-1

I’ve checked the following, but the problem remains:

  1. The Kafka topics exist and the names are correct.

  2. Network connectivity to the Kafka broker on port 9092 is fine.

  3. Splunk (the producer) is configured to send events, but no data appears in the topics.

  4. There are no relevant errors in the Kafka logs, so it’s unclear why events are not arriving.

Could you please advise on why this keeps happening and how we can resolve it?

Thanks,

0 Karma
Get Updates on the Splunk Community!

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...