skipped indexing of internal audit event will keep dropping events until indexer congestion is remedied. Check disk space and other issues that may cause indexer to block10
Can anyone pls help how to ntroubleshoot
Can you provide details of inputs.conf
and server.conf
of your indexers and heavy forwarders if you have any.
You might have a problem with your disk, perhaps the IOPS of your disk is not enough to handle your current splunk workload.
Cheers,
Dan