Monitoring Splunk

Saturati on of ev ent-pro cessing queues

khanlarloo
Explorer

hi
i have one problem,my splunk instance shows this messege in monitoring console -- > health check

Saturation of event-processing queues ------
One or more of the indexer queues on this instance is reporting an averaged fill percentage of 90 or more over the last 15 minutes. This might affect how quickly this instance indexes events.

can you tell me how can i solve my problem?

Tags (1)
0 Karma

mgaudie_splunk
Splunk Employee
Splunk Employee

Thanks for the context you provided in your comments khanlarloo. If the monitoring console is telling you that you have an indexing rate of 0 but your queues are full, this means either your disk is full, there's a hardware failure or you are out of memory.

Have a look at your workstation / server and make sure it hasn't run out of disk space or memory and that there hasn't been any other failure that would impact the operation of Splunk.

0 Karma

mgaudie_splunk
Splunk Employee
Splunk Employee

Can you share a couple of statistics on your indexing health, primarily your queue fill ratios and your indexing rate? These stats can be found in Monitoring Console > Indexing > Performance > Indexing Performance: Deployment

0 Karma

khanlarloo
Explorer

unfortunately it doesn't show any chart and is empty and it shows "no result found".
in Splunk Enterprise Data Pipeline every ques is 100.
index rate=0 status=normal fillratio=100

0 Karma

mgaudie_splunk
Splunk Employee
Splunk Employee

At the top of the Indexing Performance dashboard should be single indicators with "Total Indexing Rate" and "Average Indexing Rate" written beneath them. Are they not showing?

Also, how many indexers do you have? Only one, or is it a cluster?

0 Karma

khanlarloo
Explorer

no only one indexer,i have indexing overwie
it shows indexing rate that is 0 and the status that is normal, i don't have these items "Total Indexing Rate" and "Average Indexing Rate".

0 Karma

khanlarloo
Explorer

my disk and memory working good i don't have any issue aboute these,i see my metrics
it shows this :
6-13-2018 11:23:14.931 +0430 INFO Metrics - group=queue, name=indexqueue, blocked=true, max_size_kb=500, current_size_kb=499, current_size=971, largest_size=971, smallest_size=971

0 Karma

khanlarloo
Explorer

can you tell why my charts have no result?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...