Environment Setup:
Problem:
since upgrading Splunk and it's underlying OS, all the splunk components have become unstable and unpredictable.
Troubleshooting steps taken:
Request for help:
Hi there,
That sounds more like a VM problem if the VMs cannot even be rebooted. I would stop all of them and start one instance, check/verify its activities and if it's healthy start the next and repeat that process. If not, troubleshoot that instance on why it's not healthy and hold back until you have fix the issues and it's healthy again.
Dispatch filling up means you run a lot of searches, so check what they are and why they run so often.
Beside that disable the UI on the IDX and like @PickleRick said use any other tools available for troubleshooting.
Hope this helps ...
cheers, MuS
1. 9.3.3 is a relatively old version. Even within 9.3 line (which is still supported) you have several updates (if I'm not mistaken, the current 9.3 release is 9.3.7).
2. You did two changes at the same time (OS upgrade and Splunk upgrade). Additionally, the correlation of those upgrades with your performance problems might just be coincidental - there could be a change in how your environment is used or there might be problems with the underlying virtualization. Intermittent problems could also indicate some issues on the network level (duplicate IPs?) which would prevent your setup from behaving correctly,
Probably the main tool on Splunk's side would be the Monitoring Console. And your typical OS-level debugging tools. It's hard to say over the network what's wrong with an installation we don't see.
BTW, you shouldn't have webui enabled on the indexer.