We have recently upgraded an indexer from 8.2.6 to 9.0.2 (running on Windows) and since then we have been plagued by an intermittent issue where the indexer stops indexing new data, but otherwise functions fine. The indexing rate is 0, but it still returns search results.
Restarting the Splunk service is all that is required and it starts indexing again.
The problem seem very similar to this post, but I can't see that any of the known issues quoted relate to 9.0.2. It should be already fixed with the "server side fix" alluded to by one of the people replying to that post.
When the problem happens, we see these errors in the splunkd log of the indexer:
Sorry for the screen shots. Best I could do.
Any clues as to what is going on here?
... View more