Splunk Enterprise

Why is there Forwarder Ingestion Latency Error?

nz_021
Explorer

I have splunk instance with 9.0.3 version and my splunk keeps throwing error in Forwarder Ingestion Latency with Root Cause " Ingestion_latency_gap_multiplier' indicator exceeds configured value. Observed value is 2587595". does anyone know how to solve this problem?

 

Labels (1)
0 Karma
1 Solution

nz_021
Explorer

Halo,

i've solve this issue, the main problem is with UF in my agent. I just need to delete and reinstall the UF and the error is gone. 

View solution in original post

0 Karma

nz_021
Explorer

Halo,

i've solve this issue, the main problem is with UF in my agent. I just need to delete and reinstall the UF and the error is gone. 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

1. Verify if you do have the latency problem. Check your data coming from the given forwarder and check if it does indeed show delay in indexing.

2. It seems that it's sometimes a case of the forwarder not handling properly the $SPLUNK_HOME/var/spool/splunk/tracker.log* (based on which the alert is generated) and old values are not removed from the file but instead are reingested as the new values are appended to it. Try stopping the forwarder, removing the tracker.log file and restarting the forwarder.

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...