Monitoring Splunk

The monitor input cannot produce data because splunkd's processing queues are full, what do I do to solve this?

abazgwa21cz
Explorer

I have and issues with red status :   The monitor input cannot produce data because splunkd's processing queues are full. This will be caused by inadequate indexing or forwarding rate, or a sudden burst of incoming data.

9.PNG

10.PNG

11.PNG

i check in Indexing Performance: Instance and almost field had 100% 

and when i check CPU and memory used and license used it had alot space 

abazgwa21cz_0-1673586174855.png

 

 so how can i find the issues and can i fix this problem 

   

 

Labels (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

The logical thing to do would be to check your IO saturation.

0 Karma

abazgwa21cz
Explorer

how can i check that ? 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

iostat/iotop/vmstat, your hardware monitoring tools

Work with your infrastructure team.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...