Monitoring Splunk

Saturati on of ev ent-pro cessing queues

khanlarloo
Explorer

hi
i have one problem,my splunk instance shows this messege in monitoring console -- > health check

Saturation of event-processing queues ------
One or more of the indexer queues on this instance is reporting an averaged fill percentage of 90 or more over the last 15 minutes. This might affect how quickly this instance indexes events.

can you tell me how can i solve my problem?

Tags (1)
0 Karma

mgaudie_splunk
Splunk Employee
Splunk Employee

Thanks for the context you provided in your comments khanlarloo. If the monitoring console is telling you that you have an indexing rate of 0 but your queues are full, this means either your disk is full, there's a hardware failure or you are out of memory.

Have a look at your workstation / server and make sure it hasn't run out of disk space or memory and that there hasn't been any other failure that would impact the operation of Splunk.

0 Karma

mgaudie_splunk
Splunk Employee
Splunk Employee

Can you share a couple of statistics on your indexing health, primarily your queue fill ratios and your indexing rate? These stats can be found in Monitoring Console > Indexing > Performance > Indexing Performance: Deployment

0 Karma

khanlarloo
Explorer

unfortunately it doesn't show any chart and is empty and it shows "no result found".
in Splunk Enterprise Data Pipeline every ques is 100.
index rate=0 status=normal fillratio=100

0 Karma

mgaudie_splunk
Splunk Employee
Splunk Employee

At the top of the Indexing Performance dashboard should be single indicators with "Total Indexing Rate" and "Average Indexing Rate" written beneath them. Are they not showing?

Also, how many indexers do you have? Only one, or is it a cluster?

0 Karma

khanlarloo
Explorer

no only one indexer,i have indexing overwie
it shows indexing rate that is 0 and the status that is normal, i don't have these items "Total Indexing Rate" and "Average Indexing Rate".

0 Karma

khanlarloo
Explorer

my disk and memory working good i don't have any issue aboute these,i see my metrics
it shows this :
6-13-2018 11:23:14.931 +0430 INFO Metrics - group=queue, name=indexqueue, blocked=true, max_size_kb=500, current_size_kb=499, current_size=971, largest_size=971, smallest_size=971

0 Karma

khanlarloo
Explorer

can you tell why my charts have no result?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...