Splunk Enterprise

Why are splunk queues slightly filled after upgrade to version 9.0?

lukasmecir
Path Finder

Hi all,

I have one question:

I upgraded my Splunk deployment from 8.1.6 to 9.0.4. Deployment is: 3-nodes SH cluster, 3-nodes IDX cluster, 2 x HF, MC, SHC-D, CM, LM, DS. After upgrade I noticed one thing about queues on Monitoring Console.

Before upgrade, all queues on all IDXs have 0% fill:

queues_before_upgrade.png

But after upgrade, there is small fill (average about 5%, up to 10%) on Typing an Indexing queue:

queues_after_upgrade.png

From my point of view it is strange, because nothing changed during upgrade - HW is the same, amount of ingested data is the same, kind of data is the same, no new log source etc.

I search through documentation, but did not find anything relevant. So I would like to ask: what happens? Can it be ignored safely or there is really something wrong inside Splunk? Some config changes required because of some internal changes in Splunk? Could you share your experience with that, if you have one? Thank you in advance for any hint or glue.

Best regards

Lukas Mecir

Labels (2)
Tags (1)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...