Hi Team,
I 'm new to Splunk and need little guidance with fixing errors that occurred when I uploaded a directory < .var/log >--from ubuntu to monitor
Hi @aad,
this message should mean that you have a congestion problem on your Indexer that block indexing of data from the input.
So, what's the hardware resources of your Indexer? Splunk requests at least 12 CPUs and 12 GB RAM.
Then what are the performances of your storage? Splunk requires at least 800 IOPS, better 1200.
Then what's the your network performances?
This means that you need to re-design your architecture starting from requirements definition.
My hint is to give this assignment to a Splunk Architect.