Monitoring Splunk

Why is the pipeline suddenly blocked?

bestSplunker
Contributor

hello everyone .forgive me for not being good at English.

I encountered a problem today, A sourcetype ( sourcetype=example1 ) log was suddenly lost. My forwarding mode is as follows:

universal forwarder—>heavy forwarder—>indexer cluster

On the host with a universal forwarder, uf monitored 2 log files(corresponding to 2 sourcetypes(example1 and example2) ).

Why example1's logs Unable to send to HF, but example2's logs are successfully sent to HF and then to the indexer?

I checked my UF first. I saw this message in the splunk.log of UF.

Could not send data to output queue(parsingQueue),retrying.....

Then I look at metrics.log on HF. I saw that indexequeue, typingqueue, aggqueue and splunktcpin were blocked.

I have 3 questions about this.

1、Why is the queue suddenly blocked? I checked the monitoring history of zabbix, The HF host resources are always idle.Usually, what causes the queue to be blocked?

2、When I restart Universal forwarder, everything is back to normal.Why do I just restart the UF and the queue is working ?

3、What are the good ways to find out why the queue is blocked?

Tags (1)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...