Getting Data In

Splunk 9.2.0.1 Bug

banaie
Path Finder

Hi all,

I have faced a serious problem after upgrading indexers to 9.2.0.1! Occasionally, they stop data flow and sometimes are shown down on cluster master!

I analyzed the problem and it shows this error occasionally:

 

Search peer indexer-1 has the following message: The index processor has paused data flow. Too many tsidx files in idx=main bucket="/opt/SplunkData/db/defaultdb/hot_v1_13320" , waiting for the splunk-optimize indexing helper to catch up merging them. Ensure reasonable disk space is available, and that I/O write throughput is not compromised. 

 

 It worked smooth with same load in lower versions! I think this is a bug in new version or some more configuration is needed!

Finally, I rolled back to 9.1.3 and it now works perfectly.

 

Labels (3)
0 Karma
1 Solution

banaie
Path Finder

I can confirm that the problem is fixed on version 9.2.1! I upgraded to version 9.2.1 and those indexers work perfectly without additional configuration!

Thanks

View solution in original post

0 Karma

banaie
Path Finder

I can confirm that the problem is fixed on version 9.2.1! I upgraded to version 9.2.1 and those indexers work perfectly without additional configuration!

Thanks

0 Karma

marnall
Motivator

It might be possible to tweak the indexer queue size and change the indexes.conf settings, as per this other community post:

https://community.splunk.com/t5/Splunk-Enterprise/The-index-processor-has-paused-data-flow-How-to-op...

According to the post it should be fixed in version 9.1, but perhaps something has made the issue resurface.

0 Karma

banaie
Path Finder

@marnall 

Thanks for your reply. 

You are right! It is the same problem! But, it was said that it is fixed in 9.1 and I don't have any problem on 9.1.3! However, same bug has re-appeared on 9.2.0.1 again! 

0 Karma

marnall
Motivator

Indeed. You could try the workaround. Perhaps it still works.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Synthetic Monitoring - Resolved Incident on Detector Alerts

We’ve discovered a bug that affected the auto-clear of Synthetic Detectors in the Splunk Synthetic Monitoring ...

Video | Tom’s Smartness Journey Continues

Remember Splunk Community member Tom Kopchak? If you caught the first episode of our Smartness interview ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud? Learn how unique features like ...