Hey folks,
Did anyone ever faced a challenge on having hundreds of thousands of events stuck in phantom_retry kv store that are aged enough?
I see in the logs that quite often Splunk complains about the size of phantom_retry and I would like to see/clean up that queue and move on from there. Any idea?
I looked over the documents and there is no instruction on that matter.
Also, if I do "| inputlookup phantom_retry_lookup" it returns nothing. Using the lookup editor app I can only see this empty as well.
Any clue?
Thanks!