Monitoring Splunk

The monitor input cannot produce data because splunkd's processing queues are full, what do I do to solve this?

abazgwa21cz
Explorer

I have and issues with red status :   The monitor input cannot produce data because splunkd's processing queues are full. This will be caused by inadequate indexing or forwarding rate, or a sudden burst of incoming data.

9.PNG

10.PNG

11.PNG

i check in Indexing Performance: Instance and almost field had 100% 

and when i check CPU and memory used and license used it had alot space 

abazgwa21cz_0-1673586174855.png

 

 so how can i find the issues and can i fix this problem 

   

 

Labels (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

The logical thing to do would be to check your IO saturation.

0 Karma

abazgwa21cz
Explorer

how can i check that ? 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

iostat/iotop/vmstat, your hardware monitoring tools

Work with your infrastructure team.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...