Splunk Search

Index is hanging often

aelliott
Motivator

We recently setup DB Connect 1.1.1 and started pulling in data.
An issue we've ran into is the indexers are hanging and this did not start happening until installing DB Connect.
So I looked into it (via SoS) and saw that the index ratio is at 8.9 (for the index that DB connect input is feeding) the hour that our indexes started hanging. This has to be the reason our indexes are hanging. Is there a way to lower that indexing ratio?

0 Karma
1 Solution

aelliott
Motivator

We found that our anti-virus was locking key files and index buckets which affected splunk's indexing mechanism. This issue is now gone.

View solution in original post

0 Karma

aelliott
Motivator

We found that our anti-virus was locking key files and index buckets which affected splunk's indexing mechanism. This issue is now gone.

0 Karma

araitz
Splunk Employee
Splunk Employee

Although Splunk Answers is really useful for answering simple questions and answers, it really isn't the best place to get down to root causes of issues. Opening a support case will better allow us to help solve the problem you are encountering in your environment.

0 Karma

aelliott
Motivator

Hardly anything, I make the query so that it only pulls the last 5 minutes or so and it is usually less than 20,000 records.

I waited for it to recover and over a day it did not recover.

0 Karma

lukejadamec
Super Champion

How much data was pulled initially?

I have seen GB's worth of data from a new dbx input stall splunk, but it recovers on its own over time.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...