Monitoring Splunk

The monitor input cannot produce data because splunkd's processing queues are full, what do I do to solve this?

abazgwa21cz
Explorer

I have and issues with red status :   The monitor input cannot produce data because splunkd's processing queues are full. This will be caused by inadequate indexing or forwarding rate, or a sudden burst of incoming data.

9.PNG

10.PNG

11.PNG

i check in Indexing Performance: Instance and almost field had 100% 

and when i check CPU and memory used and license used it had alot space 

abazgwa21cz_0-1673586174855.png

 

 so how can i find the issues and can i fix this problem 

   

 

Labels (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

The logical thing to do would be to check your IO saturation.

0 Karma

abazgwa21cz
Explorer

how can i check that ? 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

iostat/iotop/vmstat, your hardware monitoring tools

Work with your infrastructure team.

0 Karma
Get Updates on the Splunk Community!

SOC Modernization: How Automation and Splunk SOAR are Shaping the Next-Gen Security ...

Security automation is no longer a luxury but a necessity. Join us to learn how Splunk ES and SOAR empower ...

Ask It, Fix It: Faster Investigations with AI Assistant in Observability Cloud

  Join us in this Tech Talk and learn about the recently launched AI Assistant in Observability Cloud. With ...

Index This | How many sides does a circle have?

  March 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...