Splunk Search

How to generate a search to find out whether indexer queues were blocked during a particular period of time?

Path Finder

Is there any search to find out whether indexer queues were blocked at a particular period of time? With Distributed Management Console (DMC), it shows only indexers queues which were full in last 15 minutes. For example, i want to know which indexer queues were full in past 2 hrs but this not possible with DMC.

0 Karma
1 Solution

SplunkTrust
SplunkTrust

How about this

index=_internal sourcetype=splunkd source=*metrics.log group=queue blocked=true

View solution in original post

Splunk Employee
Splunk Employee

@kteng2024 - Did the answer provided by somesoni2 help provide a working solution to your question? If yes, please don't forget to resolve this post by clicking "Accept". If no, please leave a comment with more feedback. Thanks!

0 Karma

SplunkTrust
SplunkTrust

How about this

index=_internal sourcetype=splunkd source=*metrics.log group=queue blocked=true

View solution in original post