hi i am getting an error in splunk as soon as i login the error is "skipped indexing of internal audit event will keep dropping events until indexer congestion is remedied. Check disk space and other issues that may cause indexer to block". please help how i should resolve this error. or what to do?
MegSplunk, are you forwarding your data from your search head? I had the same issue that was caused by an error in the configuration in outputs.conf. The error I had was an incorrectly configured path to the certificates, causing SSL connection to the indexers to fail. So, if forwarding from a search head, check that your forwarding is working.
Perhaps the original poster does not need the answer anymore, but I'm hoping MegSplunk can benefit.
Hi. I am facing the same issue. If you did find a workaround, can you please share it?