Getting Data In

Upgraded Indexer shuts down pipeline and has to be restarted?

jeremyhagand61
Communicator

We have recently upgraded an indexer from 8.2.6 to 9.0.2 (running on Windows) and since then we have been plagued by an intermittent issue where the indexer stops indexing new data, but otherwise functions fine. The indexing rate is 0, but it still returns search results.

Restarting the Splunk service is all that is required and it starts indexing again.

The problem seem very similar to this post, but I can't see that any of the known issues quoted relate to 9.0.2. It should be already fixed with the "server side fix" alluded to by one of the people replying to that post.

When the problem happens, we see these errors in the splunkd log of the indexer:

jeremyhagand61_1-1676271919661.png

jeremyhagand61_4-1676272245237.png

jeremyhagand61_2-1676271970481.png

jeremyhagand61_3-1676272009478.png

Sorry for the screen shots. Best I could do.

Any clues as to what is going on here?

 

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...