Hello everyone, i need a small help
In my search head splunkSRCH637T7.local
If I search for any logs with sourcetype , logs not getting genarating,
Health status of splund is TailReader
Root cause: the monitor input cannot produce data because splunkds processing queues are full . This will be caused by inadequate indexing or forwarding rate, or a sudden burst of incoming data,
COULD ANY ONE PLEASE HELP
PLEASE SEE MY SCREEN SHOT
Additionally look at the link below:
Please check disk space on indexers. It seems indexers are full.
Additionally look at the link below:
Hello @SinghK
Thanks , but m not sure about this.
Could you plz help me step by step procedure, it will very helpfull to me.
And also I want to confirm , this issue is from splunk forwarder or ?