Splunk 的一个Bug (Events from tracker.log have not been seen)

1:背景:Splunk version: 8.2.4

splunk 的一个alert:

Splunk 的一个Bug (Events from tracker.log have not been seen)_第1张图片

Events from tracker.log have not been seen for the last 47 seconds, which is more than the yellow threshold (45 seconds). This typically occurs when indexing or forwarding are falling behind or are blocked. 

 2: 分析:

查找一些资料,发现很多其他的版本也有这种alert,最后发现这个是Splunk 的一个bug:

2022-07-14 SPL-225807, SPL-219749 Indicator 'ingestion_latency_gap_multiplier' exceeded configured value.

This is fixed in the 9.0.1 release.

 3: 解决方法:

Create a health.conf entry in /opt/splunk/etc/system/local on the affected machines being sure to restart splunk after the entry is made.<

你可能感兴趣的:(splunk,Splunk,alert,tracker.log,Bug,blocked)