Getting Data In

Kafka Broker Error – Topics not receiving events (Status code KAFKA-1)

kn450
Explorer

Hello,

I’m experiencing an issue with my Kafka broker integration with Splunk.
The error message I’m seeing is:

Kafka Broker Error
Topic bytes in
The rate, expressed in bytes per second, of the message traffic each topic is receiving from producing clients

Error:
Kafka topics are not receiving events.
Monitor for an hour, if the status does not go back to OK, restart kafka-server. 
If this does not help, contact Splunk Support.
Status code KAFKA-1

I have monitored for more than an hour, and the status did not return to OK.
Has anyone faced this issue before or have suggestions on how to fix it?

Thanks in advance!

Labels (1)
0 Karma

PrewinThomas
Motivator

@kn450 

Did you restart kafka-server?

Also have a look at this,
#https://splunk.my.site.com/customer/s/article/KAFKA-1-and-OML-2-errors

Regards,
Prewin
If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

0 Karma

kn450
Explorer

 

Hi Prewin,

I restarted the Kafka server as suggested, but the issue persists. The Kafka broker is not receiving any events on the topics. Here is the error message I see in the dashboard:

Kafka topics are not receiving events.
Monitor for an hour, if the status does not go back to OK, restart kafka-server. If this does not help, contact Splunk Support.
Status code KAFKA-1

I’ve checked the following, but the problem remains:

  1. The Kafka topics exist and the names are correct.

  2. Network connectivity to the Kafka broker on port 9092 is fine.

  3. Splunk (the producer) is configured to send events, but no data appears in the topics.

  4. There are no relevant errors in the Kafka logs, so it’s unclear why events are not arriving.

Could you please advise on why this keeps happening and how we can resolve it?

Thanks,

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

IT Service Intelligence 5.0 Series: Your Guide to the June Launch

We are excited to announce the June release of Splunk IT Service Intelligence (ITSI) 5.0. This update ...

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...