Splunk Dev

How could i find the reason or cause of indexer down ?

kartm2020
Communicator

I just need to find the reason of indexer down in splunk

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @kartm,
it's very difficoult to understand what's happened without any info.
Anyway, start to see Splunk logs ($SPLUNK_HOME/var/log/splunk/splunkd.log or if there's a crash log.
then try to restart Splunk using console so you can see start-up messages and understand if there are error messages.
Ciao.
Giuseppe

0 Karma

soumyasaha25
Contributor

you can start off by looking at splunkd logs (index=_internal source=*splunkd.log) and also look at /var/log/messages and look for events around the time the indexer went down.

0 Karma

kartm2020
Communicator

Thank you. May i know what is the exact error message that comes in splunkd.log? Give me some sample output. it will help me a lot

0 Karma

soumyasaha25
Contributor

it is quite difficult to tell the exact message that splunk will throw when an indexer goes down since it might go down for a variety of factors (maybe the disk/memory/cpu utilization had spiked), but you should be able to figure it out from the splunkd logs just look into the error logs (index=_internal source=*splunkd.log log_level=ERROR host=).

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...