Getting Data In

Why am I getting error "No indexers have reported into this pool today" and my indexer is not indexing any data?

Afef
Communicator

Hello,

My Splunk indexer isn't indexing data and I get this error message:

No indexers have reported into this pool today 

Any help please?

Thanks

0 Karma

muszyngr
Observer

running this CLI command did it although it added the same exact stuff to the server.conf that we had there manually

splunk edit licenser-localslave -master_uri 'https://master:port'

https://docs.splunk.com/Documentation/Splunk/latest/Admin/LicenserCLIcommands#Manage_license_slaves

0 Karma

woodcock
Esteemed Legend

There are dozens of reasons, most of them firewall-related. Search here:

index=_* AND (ERR* OR FAIL* OR CANNOT OR TIMEOUT OR REFUSED OR REJECTED OR BLOCKED)
0 Karma

muszyngr
Observer

so five years later and we are getting the same error with no clear answer / solution in sight

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Can you post output of next commands:
- splunk list monitor
- splunk list tcp
- splunk list udp

Ismo

0 Karma

javiergn
Super Champion

Hi,

Have you tried running a search against that particular indexer and see if any data comes back?
For example:

index=* earliest=-1h splunk_server=YOURINDEXERHERE

If that's empty, you could try restarting your indexer and see if that helps. If not, then I'd say you need to go through the logs and probably post something else here. You could try using apps such as FireBrigade as that might help debug the problem

Thanks,
J

javiergn
Super Champion

Also when you say "pool", is that the license pool? If so, can your indexer contact your license master?
The indexer will keep indexing even if you have violated the license. Data won't be searchable but it'll still be there.

0 Karma

Afef
Communicator

Thank you for your answer, i have one splunk instance (search head + indexer).

i found this error message in the licence web page, there is no data indexed 0 Mo since last week.

0 Karma

javiergn
Super Champion

Hi, did you try to run the search I indicated above and see if that comes back with any results?

0 Karma

Afef
Communicator

Yes, no results

0 Karma

javiergn
Super Champion
  • Did you try restarting the indexer?
  • Can your universal forwarders contact the indexer?
  • Have you tried indexing something locally on the indexer/search head and see what happens? You can even use the GUI to do that

If none of these help, then we'll need you to take a look at the internal logs (index=_internal) and see if you can spot anything there. Feel free to post anything here.

0 Karma

Afef
Communicator

Hello, yes i restarted the indexer and tried to index locally but the licence still 0Mo : the indexer didn't index anything.. i didn't found error messages or important messages that could help in the logs

0 Karma

javiergn
Super Champion
  • Can you run btool and list your inputs, props, transforms, indexes and upload the results here? There might be something wrong with the configuration files.
  • Can you install the SplunkOnSplunk app and take a look at the dashboards?
  • Can you also take a look locally within the var/log directory and see if there's anything relevant there?

If we can't find out what's going on with the options above, it might be better for you to raise a support ticket with Splunk and follow their instructions.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...