Splunk Search

Getting Now skipping indexing of internal audit events, because the downstream queue is not accepting data

nls7010
Path Finder

We have set up a new system with 6 indexers and 3 search heads, we have just barely started putting in data and we are consistently getting the above message on our indexers. Not sure how to trouble-shoot to fix this issue. There is a message just before it that says Tcpout Processor: The TCP output processor has paused the data flow. Forwarding to output group all_indexers has been blocked for 10 seconds......

Any assistance would be appreciated.

0 Karma

p_gurav
Champion

1) Check indexers have enough space.
2) Check License should not cross daily limit.
3) Can you give outputs.conf file configuration? Please check if you have only one server added below the autoLB = true

Also run

./splunk cmd btool check

to check any inconsistencies in the configuration files which might be causing it.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...