Still VERY new to Splunk here. But I had a issue I was looking for input on where to start with troubleshooting.
Our company has an index splunk service die somepoint yesterday. I started it again with ./splunk start and it went into a fsck mode and was doing that for roughly an hour then worked. This mornming A different indexer has the same issue.
Any idea what could be happening? Where I would start troubleshooting something like that?
Well, I guess I would check for a crash log and see if there was any unusual activity (CPU, disk, memory) according to any data you gathered, as well as the splunk internal logs files. Those are in $SPLUNK_HOME/var/log/splunk, but also indexed into the _internal index.