Getting Data In

Where do I start with troubleshooting Parsing Queue issues on a UF?

daniel333
Builder

All,

I have SplunkAdmins app installed and received alerts showing me that my Universal Forwarder on a series of Windows servers are having their "1 - Parsing Queue" backup pretty often. I don't have much installed there except Splunk_TA_windows. Point me to any good docs on troubleshooting Parsing Queue backups on the UF itself?

thanks
-Daniel

0 Karma
1 Solution

mayurr98
Super Champion

You should start looking for

index=_internal component=metrics name=parsingQueue WARN OR ERROR

View solution in original post

daniel333
Builder

Tracked down the problem on the UF's parsing queue to basically a limits.conf setting on KB per second. Needed closer to 1 meg per second from these hosts and had it set to 512. Once I tuned that the queue alerts went away.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The UF does not have a parsing queue. The error message you cite is part of the "Indexer Queues May Have Issues" alert so I suspect your configuration has mixed up indexer and UF host names. Check the setting for the indexerhosts macro.

---
If this reply helps you, Karma would be appreciated.
0 Karma

mayurr98
Super Champion

You should start looking for

index=_internal component=metrics name=parsingQueue WARN OR ERROR
Get Updates on the Splunk Community!

Understanding Generative AI Techniques and Their Application in Cybersecurity

Watch On-Demand Artificial intelligence is the talk of the town nowadays, with industries of all kinds ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Using the Splunk Threat Research Team’s Latest Security Content

REGISTER HERE Tech Talk | Security Edition Did you know the Splunk Threat Research Team regularly releases ...