Getting Data In

Indexers outage - What can I do to troubleshoot?

GaetanVP
Contributor

Hello Splunkers, 

I am facing a problem with my indexers that are not able to index anymore. Neither the data forwarder to those indexers, neither the internal Splunk logs... I even tried to index data (simple txt file) directly from the indexer GUI, I do not get any error but my selected indexe will not be filled/updated.

Any clue what I can do to troubleshoot ? There is nothing in splunkd.log file, what other logs should I check?

Regards,
GaetanVP

Labels (1)
Tags (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @GaetanVP,

did you checked if you have sufficient disk space on indexers? usually this is the reason for stop internal indexing.

If you have sufficient disk space and resources, open a ticket to Splunk Support.

Ciao.

Giuseppe

GaetanVP
Contributor

Hello @gcusello, sorry for the late reply,

Just for information the problem was linked to a bad outputs.conf I put on my Indexers. As you know, having issues with outgoing traffic would impact the data flow in a way that tcpout queue would fill up, that was the case.

Thanks,

GaetanVP

Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...