Getting Data In

Can you help me troubleshoot my issue involving sending data to output queue(parsing queue)?

ankithnageshshe
Path Finder

Hello Splunkers,

Lately, we have been facing issues in on-boarding data due to the “Could not send…..parsing queue full” issue whenever there is a data burst.

We have been setting maxkbps in limits.conf to unlimited(0) and parsing queue size to 10 MB from 512kb temporarily as a workaround.

What is the Splunk recommended best practice to address this issue?

Splunk universal forwarder version - 6.4

0 Karma

mstjohn_splunk
Splunk Employee
Splunk Employee

hi @ankithnageshshetty,

Did the answer below solve your problem? If so, please resolve this post by approving it! If your problem is still not solved, keep us updated so that someone else can help ya. Thanks for posting!

0 Karma

vinkumar_splunk
Splunk Employee
Splunk Employee

Check the below link:

https://answers.splunk.com/answers/5590/could-not-send-data-to-the-output-queue.html

Most cases this occur due to congestion on the indexer side. you need to look into the "QUEUES" and sort out based on which queue is filled.

For example, look for line breaking/truncating for parsing queue; dateparserververbose for aggregation queue, regex for typing queue and check the IOPS value ( random seeks ) if the indexing queue is filled, ensure that you have 800 IOPS value on the indexer.

DId the temporary workaround helped?

Get Updates on the Splunk Community!

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...

What's New in Splunk Cloud Platform 9.0.2208?!

Howdy!  We are happy to share the newest updates in Splunk Cloud Platform 9.0.2208! Analysts can benefit ...

Admin Console: A Single, Unified Interface for All Your Cloud Admin Needs

WATCH NOWJoin us to learn how the admin console can save you time and give you more control over the Splunk® ...