Getting Data In

Splunk isn't working like it used to. Why?

AllenRed
New Member

I have one Splunk server working with one client. Currently when I search for Splunk logs (in the GUI with the source= setting in the free text field), I don't see newly updated files. Previously Splunk worked very fast. I saw time stamps of files that were updated almost instantly. A couple days ago, my Splunk enterprise license expired. The free version should allow for ample indexing, right? I only have one client server.

For the messages in the GUI version of Splunk, I see:

"skipped indexing of internal audit event will keep dropping events until indexer congestion is remedied. Check disk space and other issues that may cause indexer to block"

What should I do about this message? Why won't the search results in Splunk be for the most recent files like they used to be?

Tags (2)
0 Karma

jayannah
Builder

Yes, the splunk continue to index upto 500MB per day even after expiry.. But answer for the message you is described in this Q & A http://answers.splunk.com/answers/44552/indexing-congestion-consistenly-happening.html

0 Karma

dolivasoh
Contributor

The free license only allows for 500MB/day of indexing. If you've been running on that for more than 3 days, your searching ability is probably disabled as your indexer is in violation.

As for "skipped indexing of internal audit event will keep dropping events until indexer congestion is remedied", it says to Check disk space and other issues that may cause indexer to block. so I would go and check to make sure you have enough disk space as indexing will halt at the configured level of free space.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...