Getting Data In

Upgraded Indexer shuts down pipeline and has to be restarted?

jeremyhagand61
Communicator

We have recently upgraded an indexer from 8.2.6 to 9.0.2 (running on Windows) and since then we have been plagued by an intermittent issue where the indexer stops indexing new data, but otherwise functions fine. The indexing rate is 0, but it still returns search results.

Restarting the Splunk service is all that is required and it starts indexing again.

The problem seem very similar to this post, but I can't see that any of the known issues quoted relate to 9.0.2. It should be already fixed with the "server side fix" alluded to by one of the people replying to that post.

When the problem happens, we see these errors in the splunkd log of the indexer:

jeremyhagand61_1-1676271919661.png

jeremyhagand61_4-1676272245237.png

jeremyhagand61_2-1676271970481.png

jeremyhagand61_3-1676272009478.png

Sorry for the screen shots. Best I could do.

Any clues as to what is going on here?

 

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...