Monitoring Splunk

getting error in splunk 4.2 reagarding indexers

rupesh212121
Explorer

hi i am getting an error in splunk as soon as i login the error is "skipped indexing of internal audit event will keep dropping events until indexer congestion is remedied. Check disk space and other issues that may cause indexer to block". please help how i should resolve this error. or what to do?

Tags (1)

echalex
Builder

MegSplunk, are you forwarding your data from your search head? I had the same issue that was caused by an error in the configuration in outputs.conf. The error I had was an incorrectly configured path to the certificates, causing SSL connection to the indexers to fail. So, if forwarding from a search head, check that your forwarding is working.

Perhaps the original poster does not need the answer anymore, but I'm hoping MegSplunk can benefit.

0 Karma

MegSplunk
Path Finder

Hi. I am facing the same issue. If you did find a workaround, can you please share it?

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...