Monitoring Splunk

getting error in splunk 4.2 reagarding indexers

rupesh212121
Explorer

hi i am getting an error in splunk as soon as i login the error is "skipped indexing of internal audit event will keep dropping events until indexer congestion is remedied. Check disk space and other issues that may cause indexer to block". please help how i should resolve this error. or what to do?

Tags (1)

echalex
Builder

MegSplunk, are you forwarding your data from your search head? I had the same issue that was caused by an error in the configuration in outputs.conf. The error I had was an incorrectly configured path to the certificates, causing SSL connection to the indexers to fail. So, if forwarding from a search head, check that your forwarding is working.

Perhaps the original poster does not need the answer anymore, but I'm hoping MegSplunk can benefit.

0 Karma

MegSplunk
Path Finder

Hi. I am facing the same issue. If you did find a workaround, can you please share it?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...