Getting Data In

nullqueue or nullQueue ?

yannK
Splunk Employee
Splunk Employee

I saw this in transforms.conf : should if be nullQueue or nullqueue ?

[send_to_nullqueue]
DEST_KEY = queue
REGEX    = .
FORMAT   = nullQueue
Tags (1)
1 Solution

lguinn2
Legend

nullQueue is the correct spelling.

View solution in original post

lguinn2
Legend

nullQueue is the correct spelling.

yannK
Splunk Employee
Splunk Employee

Thank you, I tested with the wrong one, and it created 2 lines in metrics, that look identical but are not.
`
10-02-2012 08:26:13.261 -0400 INFO Metrics - group=queue, name=nullqueue, max_size_kb=500, current_size_kb=0, current_size=0, largest_size=0, smallest_size=0
10-02-2012 08:26:13.261 -0400 INFO Metrics - group=queue, name=nullqueue, blocked=true, max_size_kb=500, current_size_kb=499, current_size=998, largest_size=998, smallest_size=998

and when the wrong queue one was full, my indexer was buster, unable to accept any data. So please use the correct nullQueue.
`

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...