Splunk Search

Getting Now skipping indexing of internal audit events, because the downstream queue is not accepting data

nls7010
Path Finder

We have set up a new system with 6 indexers and 3 search heads, we have just barely started putting in data and we are consistently getting the above message on our indexers. Not sure how to trouble-shoot to fix this issue. There is a message just before it that says Tcpout Processor: The TCP output processor has paused the data flow. Forwarding to output group all_indexers has been blocked for 10 seconds......

Any assistance would be appreciated.

0 Karma

p_gurav
Champion

1) Check indexers have enough space.
2) Check License should not cross daily limit.
3) Can you give outputs.conf file configuration? Please check if you have only one server added below the autoLB = true

Also run

./splunk cmd btool check

to check any inconsistencies in the configuration files which might be causing it.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...