Monitoring Splunk

getting error in splunk 4.2 reagarding indexers

rupesh212121
Explorer

hi i am getting an error in splunk as soon as i login the error is "skipped indexing of internal audit event will keep dropping events until indexer congestion is remedied. Check disk space and other issues that may cause indexer to block". please help how i should resolve this error. or what to do?

Tags (1)

echalex
Builder

MegSplunk, are you forwarding your data from your search head? I had the same issue that was caused by an error in the configuration in outputs.conf. The error I had was an incorrectly configured path to the certificates, causing SSL connection to the indexers to fail. So, if forwarding from a search head, check that your forwarding is working.

Perhaps the original poster does not need the answer anymore, but I'm hoping MegSplunk can benefit.

0 Karma

MegSplunk
Path Finder

Hi. I am facing the same issue. If you did find a workaround, can you please share it?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...