Getting Data In

stopping all listening ports?

piebob
Splunk Employee
Splunk Employee

reposting for a user over on the forums:

I bounced my indexer and now my forwarders are unable to connect. I just upgraded this indexer to 4.1.2 (although it's been working for hours since the upgrade).

The error in the splunkd.log is: TcpInputProc - Stopping all listening ports. Queues blocked for more than 300 seconds

What does this mean? I can't seem to find any relevant info. This is a 64b OpenSuse10.3 box.

1 Solution

gkanapathy
Splunk Employee
Splunk Employee

For whatever reason, indexing is not going on, so the indexer has stopped accepting data on input ports. It might be because you're out of space, or your indexes are otherwise locked out (possibly because permissions aren't enabled). It's seems likely there will be other errors in splunkd.log, or clues in metrics.log

View solution in original post

Chris_R_
Splunk Employee
Splunk Employee

I was actually working with this user in the official support channels, I think the problem was his inputs.conf had the queues specified with
[inputstanza]
queue = parsingQueue

Looking at his metric queue diagnostics he was getting over 1000 events in his parsing queue even at fairly slow times. We removed the queue setting entirely and he's no longer getting queue blocked message, queue's dont have to be explicitly specified in 4.x. as splunk should default to parsing queue for all stanzas.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

For whatever reason, indexing is not going on, so the indexer has stopped accepting data on input ports. It might be because you're out of space, or your indexes are otherwise locked out (possibly because permissions aren't enabled). It's seems likely there will be other errors in splunkd.log, or clues in metrics.log

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automated Threat Analysis: Available in ES Premier

Automated Threat Analysis: Centralize and Accelerate Phishing Investigations in Splunk Enterprise ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...