received event for unconfigured/disabled index=’xxxx’ with source=’source::yyyy’ host=’host::zzzz’ sourcetype=’sourcetype::stash’ ( 1 missing total ) Please find below some of the short cuts being used in
Could not send data to output queue (parsingQueue), retrying… You can increase the file descriptors, etc. but you will probably still have performance issues. I
Could not send data to output queue (parsingQueue), retrying… The TailingProcessor message means that it was unable to insert data into the parsingQueue, which, as
Linux transparent hugetables support, enabled=”always” defrag=”always” 1. Go to your Search Head OR Indexer and open a GUI : https://:8000 2. Go to
The hard fd limit is lower than the recommended value. The hard limit is ‘4096‘ The recommended value is ‘64000‘. 1. Go to your Search
Usage of Splunk commands : ADDCOLTOTALS is as follows : Computes and appends a new result with fields that represent the sum of all values
Usage of Splunk EVAL Function : CASE This function takes pairs of arguments X and Y. X arguments are Boolean expressions When the first X
Usage of Splunk EVAL Function : ABS is as follows : This Function takes the “Numeric Value” as an Input and returns its Absolute Value.
Usage of Splunk commands : ACCUM is as follows : Keeps a running total of a specified numeric field.
We might need to replace the Master-Node for either of these reasons : 1. The Node Fails 2. We need to move the Master to