Splunk Search

Getting Now skipping indexing of internal audit events, because the downstream queue is not accepting data

nls7010
Path Finder

We have set up a new system with 6 indexers and 3 search heads, we have just barely started putting in data and we are consistently getting the above message on our indexers. Not sure how to trouble-shoot to fix this issue. There is a message just before it that says Tcpout Processor: The TCP output processor has paused the data flow. Forwarding to output group all_indexers has been blocked for 10 seconds......

Any assistance would be appreciated.

0 Karma

p_gurav
Champion

1) Check indexers have enough space.
2) Check License should not cross daily limit.
3) Can you give outputs.conf file configuration? Please check if you have only one server added below the autoLB = true

Also run

./splunk cmd btool check

to check any inconsistencies in the configuration files which might be causing it.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...