Getting Data In

Why am I getting error "No indexers have reported into this pool today" and my indexer is not indexing any data?

Communicator

Hello,

My Splunk indexer isn't indexing data and I get this error message:

No indexers have reported into this pool today 

Any help please?

Thanks

0 Karma

New Member

running this CLI command did it although it added the same exact stuff to the server.conf that we had there manually

splunk edit licenser-localslave -master_uri 'https://master:port'

https://docs.splunk.com/Documentation/Splunk/latest/Admin/LicenserCLIcommands#Manage_license_slaves

0 Karma

Esteemed Legend

There are dozens of reasons, most of them firewall-related. Search here:

index=_* AND (ERR* OR FAIL* OR CANNOT OR TIMEOUT OR REFUSED OR REJECTED OR BLOCKED)
0 Karma

New Member

so five years later and we are getting the same error with no clear answer / solution in sight

0 Karma

Champion

Can you post output of next commands:
- splunk list monitor
- splunk list tcp
- splunk list udp

Ismo

0 Karma

SplunkTrust
SplunkTrust

Hi,

Have you tried running a search against that particular indexer and see if any data comes back?
For example:

index=* earliest=-1h splunk_server=YOURINDEXERHERE

If that's empty, you could try restarting your indexer and see if that helps. If not, then I'd say you need to go through the logs and probably post something else here. You could try using apps such as FireBrigade as that might help debug the problem

Thanks,
J

SplunkTrust
SplunkTrust

Also when you say "pool", is that the license pool? If so, can your indexer contact your license master?
The indexer will keep indexing even if you have violated the license. Data won't be searchable but it'll still be there.

0 Karma

Communicator

Thank you for your answer, i have one splunk instance (search head + indexer).

i found this error message in the licence web page, there is no data indexed 0 Mo since last week.

0 Karma

SplunkTrust
SplunkTrust

Hi, did you try to run the search I indicated above and see if that comes back with any results?

0 Karma

Communicator

Yes, no results

0 Karma

SplunkTrust
SplunkTrust
  • Did you try restarting the indexer?
  • Can your universal forwarders contact the indexer?
  • Have you tried indexing something locally on the indexer/search head and see what happens? You can even use the GUI to do that

If none of these help, then we'll need you to take a look at the internal logs (index=_internal) and see if you can spot anything there. Feel free to post anything here.

0 Karma

Communicator

Hello, yes i restarted the indexer and tried to index locally but the licence still 0Mo : the indexer didn't index anything.. i didn't found error messages or important messages that could help in the logs

0 Karma

SplunkTrust
SplunkTrust
  • Can you run btool and list your inputs, props, transforms, indexes and upload the results here? There might be something wrong with the configuration files.
  • Can you install the SplunkOnSplunk app and take a look at the dashboards?
  • Can you also take a look locally within the var/log directory and see if there's anything relevant there?

If we can't find out what's going on with the options above, it might be better for you to raise a support ticket with Splunk and follow their instructions.

0 Karma