Splunk Enterprise

splunkd's processing queues are full in Heavy Forwarder

Eshwar
Engager

Hi Experts,

We have recently installed Heavy Forwarder and disabled the indexing on it and also we are not forwarding any data from forwarders as of now but all the queue are full in HWF. Don't understand how HWF is full simply without getting any data. Please suggest how to clear them and make it as normal.

Eshwar_0-1689143031022.png

Regards,

Eshwar

 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Are you sure the HF is not forwarding any data?  By default, it will send its own logs.  btool can show what inputs are enabled.

splunk btool inputs list --debug

The fix is to remove whatever is blocking the queues.  In this case, make sure the HF has indexers to send to.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Eshwar
Engager

Hi @richgalloway ,

 We are forwarding the data to Cloud instance from HWF but we don't see any data on Cloud instance. Can you suggest how to remove the blocking queues in HWF as my understand disable is the option right?

Regards,

Eshwar

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The HF should be logging messages about why it can't send to Splunk Cloud.  Please share those messages so we can suggest solutions.  Once that is resolved, the queues will decrease.

Confirm your network allows connections from the HF to your Splunk Cloud indexers.

Verify you have installed the "Universal Forwarder" app from your Splunk Cloud instance on the HF.  Yes, an app called "Universal Forwarder" really does go on a Heavy Forwarder.

Disabling inputs will prevent more data from being added to the queues, but will not clear the queues.  Restarting the HF will clear the in-memory queues, however.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...