Monitoring Splunk

Why is the pipeline suddenly blocked?

bestSplunker
Contributor

hello everyone .forgive me for not being good at English.

I encountered a problem today, A sourcetype ( sourcetype=example1 ) log was suddenly lost. My forwarding mode is as follows:

universal forwarder—>heavy forwarder—>indexer cluster

On the host with a universal forwarder, uf monitored 2 log files(corresponding to 2 sourcetypes(example1 and example2) ).

Why example1's logs Unable to send to HF, but example2's logs are successfully sent to HF and then to the indexer?

I checked my UF first. I saw this message in the splunk.log of UF.

Could not send data to output queue(parsingQueue),retrying.....

Then I look at metrics.log on HF. I saw that indexequeue, typingqueue, aggqueue and splunktcpin were blocked.

I have 3 questions about this.

1、Why is the queue suddenly blocked? I checked the monitoring history of zabbix, The HF host resources are always idle.Usually, what causes the queue to be blocked?

2、When I restart Universal forwarder, everything is back to normal.Why do I just restart the UF and the queue is working ?

3、What are the good ways to find out why the queue is blocked?

Tags (1)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...