Splunk Enterprise

splunkd's processing queues are full in Heavy Forwarder

Eshwar
Engager

Hi Experts,

We have recently installed Heavy Forwarder and disabled the indexing on it and also we are not forwarding any data from forwarders as of now but all the queue are full in HWF. Don't understand how HWF is full simply without getting any data. Please suggest how to clear them and make it as normal.

Eshwar_0-1689143031022.png

Regards,

Eshwar

 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Are you sure the HF is not forwarding any data?  By default, it will send its own logs.  btool can show what inputs are enabled.

splunk btool inputs list --debug

The fix is to remove whatever is blocking the queues.  In this case, make sure the HF has indexers to send to.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Eshwar
Engager

Hi @richgalloway ,

 We are forwarding the data to Cloud instance from HWF but we don't see any data on Cloud instance. Can you suggest how to remove the blocking queues in HWF as my understand disable is the option right?

Regards,

Eshwar

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The HF should be logging messages about why it can't send to Splunk Cloud.  Please share those messages so we can suggest solutions.  Once that is resolved, the queues will decrease.

Confirm your network allows connections from the HF to your Splunk Cloud indexers.

Verify you have installed the "Universal Forwarder" app from your Splunk Cloud instance on the HF.  Yes, an app called "Universal Forwarder" really does go on a Heavy Forwarder.

Disabling inputs will prevent more data from being added to the queues, but will not clear the queues.  Restarting the HF will clear the in-memory queues, however.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...