Splunk Search

Getting Now skipping indexing of internal audit events, because the downstream queue is not accepting data

nls7010
Path Finder

We have set up a new system with 6 indexers and 3 search heads, we have just barely started putting in data and we are consistently getting the above message on our indexers. Not sure how to trouble-shoot to fix this issue. There is a message just before it that says Tcpout Processor: The TCP output processor has paused the data flow. Forwarding to output group all_indexers has been blocked for 10 seconds......

Any assistance would be appreciated.

0 Karma

p_gurav
Champion

1) Check indexers have enough space.
2) Check License should not cross daily limit.
3) Can you give outputs.conf file configuration? Please check if you have only one server added below the autoLB = true

Also run

./splunk cmd btool check

to check any inconsistencies in the configuration files which might be causing it.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...