Monitoring Splunk

getting error in splunk 4.2 reagarding indexers

rupesh212121
Explorer

hi i am getting an error in splunk as soon as i login the error is "skipped indexing of internal audit event will keep dropping events until indexer congestion is remedied. Check disk space and other issues that may cause indexer to block". please help how i should resolve this error. or what to do?

Tags (1)

echalex
Builder

MegSplunk, are you forwarding your data from your search head? I had the same issue that was caused by an error in the configuration in outputs.conf. The error I had was an incorrectly configured path to the certificates, causing SSL connection to the indexers to fail. So, if forwarding from a search head, check that your forwarding is working.

Perhaps the original poster does not need the answer anymore, but I'm hoping MegSplunk can benefit.

0 Karma

MegSplunk
Path Finder

Hi. I am facing the same issue. If you did find a workaround, can you please share it?

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...