When I run the following -
index=_internal host=x1209 group=queue blocked name=indexqueue | timechart count by queue
I don't see the results matching the -
index=_internal host=x1209 group=queue unblocked name=indexqueue | timechart count by queue
Meaning, blocked versus unblocked.
My problem is that only by bouncing Splunk, the 9997 port becomes open and it starts indexing. According to the License Usage - Previous 30 Days , this indexer hasn't indexed any data for three days until the bounce.
... View more