Getting Data In

Why can't we see indexer internal logs?

bhsakarchourasi
Path Finder

Hi All,

we are unable to see the indexers internal logs in _internal index, except mongodb logs. we verified that the input configuration is present in default inputs.conf but while checking in splunkd.log there is no TailReader process logs, the only logs which is related to seekptr (generally seen when there is rollover of the log file). We even tried configuring inputs.conf with different index and sourcetype for splunkd.log but it didn't worked.

Also there are almost half of the UFs stopped reporting to indexers. there are 6 indexers in cluster.

Any idea about the issue will be very helpful.

 

Thanks,

Bhaskar    

Labels (1)
Tags (1)
0 Karma
1 Solution

bhsakarchourasi
Path Finder

This is solved but I am still not convinced with resolution, after spending hours on troubleshooting we circled back to the changes performed in last one week, then found a small typo in props.conf of one of the app pushed to indexers and search heads. disabling that app in indexers resolved the issue (later corrected the typo in idx and SHs), not sure how a typo in a app halted internal logs of indexers and some of the UFs. We have asked splunk to help investigate the issue.   

View solution in original post

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Can you check that those logs are present and working on filesystem level? There could be some event on those which told the reason why splunk cannot index those?

bhsakarchourasi
Path Finder

This is solved but I am still not convinced with resolution, after spending hours on troubleshooting we circled back to the changes performed in last one week, then found a small typo in props.conf of one of the app pushed to indexers and search heads. disabling that app in indexers resolved the issue (later corrected the typo in idx and SHs), not sure how a typo in a app halted internal logs of indexers and some of the UFs. We have asked splunk to help investigate the issue.   

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @bhsakarchourasi,

it depends on what's the type you found.

Anyway, good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated by all the contributors 😉

isoutamo
SplunkTrust
SplunkTrust

Nice to hear that you solved it. One way to analyze it more, is install all your configurations to standalone instance just like those was on production. Then use btool to check how those are expanded on that node. That way you see why that typo has this kind of side effect.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...