1:背景:Splunk version: 8.2.4
splunk 的一个alert:
Events from tracker.log have not been seen for the last 47 seconds, which is more than the yellow threshold (45 seconds). This typically occurs when indexing or forwarding are falling behind or are blocked.
2: 分析:
查找一些资料,发现很多其他的版本也有这种alert,最后发现这个是Splunk 的一个bug:
2022-07-14 | SPL-225807, SPL-219749 | Indicator 'ingestion_latency_gap_multiplier' exceeded configured value. |
This is fixed in the 9.0.1 release.
3: 解决方法:
Create a health.conf entry in /opt/splunk/etc/system/local on the affected machines being sure to restart splunk after the entry is made.<