<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What will happen after splunk universal forwarder reached throughput limit in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/What-will-happen-after-splunk-universal-forwarder-reached/m-p/658216#M17412</link>
    <description>&lt;P&gt;i have set this method, but it's still not working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;let me explain my sitution as below.&lt;/P&gt;&lt;P&gt;I need to monitor the folders obtained by mounting Azure's "file share" (like pvc-xxxx),&lt;/P&gt;&lt;P&gt;and the log generation policy as i mentioned before,&amp;nbsp; it will generate new folder named today's date,&amp;nbsp;&lt;/P&gt;&lt;P&gt;/mnt/xxx/2023-09-20&lt;/P&gt;&lt;P&gt;/mnt/xxx/2023-09-21&lt;/P&gt;&lt;P&gt;....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and the log&amp;nbsp;naming policy is&amp;nbsp;&lt;/P&gt;&lt;P&gt;/mnt/xxx/2023-09-20/open-development-abcd.log&lt;/P&gt;&lt;P&gt;/mnt/xxx/2023-09-20/open-development-efgh.log&lt;/P&gt;&lt;P&gt;/mnt/xxx/2023-09-21/open-development-abcd.log&lt;/P&gt;&lt;P&gt;/mnt/xxx/2023-09-21/open-development-efgh.log&lt;/P&gt;&lt;P&gt;the log name is same, but the content is differernt,&amp;nbsp;&lt;/P&gt;&lt;P&gt;and then, it always stall ingest data at next day,&amp;nbsp; and i need to restart it, and then, the data will be collected, today 2023-09-21, i try to place some test file in&amp;nbsp;2023-09-21 folder by manully before restart , looks like the UF unable to detect them, so i restart it finally, the data was collected.&amp;nbsp;&lt;/P&gt;&lt;P&gt;my input as below:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor://mnt/xxx/*/open-development*.log]
disabled=0
host=xxxx
index=xxx
soucetype=xxx
_TCP_ROUTING=xxx
crcSalt=&amp;lt;SOURCE&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please help try to locate the root cause, thanks so much. please&lt;/P&gt;</description>
    <pubDate>Thu, 21 Sep 2023 05:47:21 GMT</pubDate>
    <dc:creator>Zane</dc:creator>
    <dc:date>2023-09-21T05:47:21Z</dc:date>
    <item>
      <title>What will happen after splunk universal forwarder reached throughput limit</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-will-happen-after-splunk-universal-forwarder-reached/m-p/656181#M17245</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I want to know that what will happen after splunk universal forwarder reached throughput limit, because i found my universal forwarder is stop ingest the data at a certain monment every day, and i don't know waht happend here, and i just set up the thruput in limits.conf, and restart the UF, the remain data will be collected,&amp;nbsp;&lt;BR /&gt;although i'm not sure if it will still be effective next time...&lt;/P&gt;&lt;P&gt;so the&amp;nbsp;throughput limit reached, the Splunk UF will stop collecting data until next restart?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2023 03:19:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-will-happen-after-splunk-universal-forwarder-reached/m-p/656181#M17245</guid>
      <dc:creator>Zane</dc:creator>
      <dc:date>2023-08-31T03:19:11Z</dc:date>
    </item>
    <item>
      <title>Re: What will happen after splunk universal forwarder reached throughput limit</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-will-happen-after-splunk-universal-forwarder-reached/m-p/656256#M17247</link>
      <description>&lt;P&gt;What do you mean by "throughput limit"?&amp;nbsp; The UF has a rate limit which defaults to 256kbps.&amp;nbsp; The UF will read data at that rate until it catches up (if ever), but it will not stop reading.&lt;/P&gt;&lt;P&gt;Tell us more about the symptoms so we can offer suggestions.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2023 12:04:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-will-happen-after-splunk-universal-forwarder-reached/m-p/656256#M17247</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-08-31T12:04:14Z</dc:date>
    </item>
    <item>
      <title>Re: What will happen after splunk universal forwarder reached throughput limit</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-will-happen-after-splunk-universal-forwarder-reached/m-p/656355#M17262</link>
      <description>&lt;P&gt;I ask this question&amp;nbsp; because i occured a issues about UF collection,&lt;/P&gt;&lt;P&gt;i have some floder named as date, for example, date is 2023-08-31, and then the log file will be placed here, and so on,&amp;nbsp; but the log file name may same，but the content is different,&amp;nbsp; and then i found there is a so&amp;nbsp;&lt;SPAN class=""&gt;strange&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;phenomena, Collecting data always stops the previous day，for example, today is 2023-09-01, it stop at yesterday 2023-08-31, It will not collect the logs generated today， the file names in these two folders are the same, but the content，size，modified time is different, and I have also added the crcSalt parameter , and it will collect data again after i restart UF,&amp;nbsp; it&amp;nbsp;cycles this phenomenon every day until I restart.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;so is there any parameter for this? thanks so much.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;my inputs as below:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;[monitor:///mnt/business/pvc-6e1ed89e/privopen/*/open-test*.log]&lt;BR /&gt;disabled = 0&lt;BR /&gt;host = myhost&lt;BR /&gt;index = test_index&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;crcSalt=&amp;lt;SOURCE&amp;gt;&lt;BR /&gt;sourcetype = test_business&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;_TCP_ROUTING=azure_hf&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Fri, 01 Sep 2023 05:28:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-will-happen-after-splunk-universal-forwarder-reached/m-p/656355#M17262</guid>
      <dc:creator>Zane</dc:creator>
      <dc:date>2023-09-01T05:28:06Z</dc:date>
    </item>
    <item>
      <title>Re: What will happen after splunk universal forwarder reached throughput limit</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-will-happen-after-splunk-universal-forwarder-reached/m-p/656358#M17263</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;could it be that the start of this file is same in every day? That way it could be seen as a same file by splunk? You could try to add&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;initCrcLength = &amp;lt;integer&amp;gt;
* How much of a file, in bytes, that the input reads before trying to
  identify whether it has already seen the file.
* You might want to adjust this if you have many files with common
  headers (comment headers, long CSV headers, etc) and recurring filenames.
* Cannot be less than 256 or more than 1048576.
* CAUTION: Improper use of this setting causes data to be re-indexed. You
  might want to consult with Splunk Support before adjusting this value - the
  default is fine for most installations.
* Default: 256 (bytes)&lt;/PRE&gt;&lt;P&gt;into inputs.conf to tackle that. Probably this is not enough as if the content has just change? Then you can try to add CHECK_METHOD into props.conf&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;File checksum configuration&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;CHECK_METHOD = [endpoint_md5|entire_md5|modtime]
* Set CHECK_METHOD to "endpoint_md5" to have Splunk software perform a checksum
  of the first and last 256 bytes of a file. When it finds matches, Splunk
  software lists the file as already indexed and indexes only new data, or
  ignores it if there is no new data.
* Set CHECK_METHOD to "entire_md5" to use the checksum of the entire file.
* Set CHECK_METHOD to "modtime" to check only the modification time of the
  file.
* Settings other than "endpoint_md5" cause Splunk software to index the entire
  file for each detected change.
* This option is only valid for [source::&amp;lt;source&amp;gt;] stanzas.
* This setting applies at input time, when data is first read by Splunk
  software, such as on a forwarder that has configured inputs acquiring the
  data.
* Default: endpoint_md5

initCrcLength = &amp;lt;integer&amp;gt;
* See documentation in inputs.conf.spec.&lt;/PRE&gt;&lt;P&gt;I hope that those will help you.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2023 06:03:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-will-happen-after-splunk-universal-forwarder-reached/m-p/656358#M17263</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-09-01T06:03:07Z</dc:date>
    </item>
    <item>
      <title>Re: What will happen after splunk universal forwarder reached throughput limit</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-will-happen-after-splunk-universal-forwarder-reached/m-p/658216#M17412</link>
      <description>&lt;P&gt;i have set this method, but it's still not working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;let me explain my sitution as below.&lt;/P&gt;&lt;P&gt;I need to monitor the folders obtained by mounting Azure's "file share" (like pvc-xxxx),&lt;/P&gt;&lt;P&gt;and the log generation policy as i mentioned before,&amp;nbsp; it will generate new folder named today's date,&amp;nbsp;&lt;/P&gt;&lt;P&gt;/mnt/xxx/2023-09-20&lt;/P&gt;&lt;P&gt;/mnt/xxx/2023-09-21&lt;/P&gt;&lt;P&gt;....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and the log&amp;nbsp;naming policy is&amp;nbsp;&lt;/P&gt;&lt;P&gt;/mnt/xxx/2023-09-20/open-development-abcd.log&lt;/P&gt;&lt;P&gt;/mnt/xxx/2023-09-20/open-development-efgh.log&lt;/P&gt;&lt;P&gt;/mnt/xxx/2023-09-21/open-development-abcd.log&lt;/P&gt;&lt;P&gt;/mnt/xxx/2023-09-21/open-development-efgh.log&lt;/P&gt;&lt;P&gt;the log name is same, but the content is differernt,&amp;nbsp;&lt;/P&gt;&lt;P&gt;and then, it always stall ingest data at next day,&amp;nbsp; and i need to restart it, and then, the data will be collected, today 2023-09-21, i try to place some test file in&amp;nbsp;2023-09-21 folder by manully before restart , looks like the UF unable to detect them, so i restart it finally, the data was collected.&amp;nbsp;&lt;/P&gt;&lt;P&gt;my input as below:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor://mnt/xxx/*/open-development*.log]
disabled=0
host=xxxx
index=xxx
soucetype=xxx
_TCP_ROUTING=xxx
crcSalt=&amp;lt;SOURCE&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please help try to locate the root cause, thanks so much. please&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2023 05:47:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-will-happen-after-splunk-universal-forwarder-reached/m-p/658216#M17412</guid>
      <dc:creator>Zane</dc:creator>
      <dc:date>2023-09-21T05:47:21Z</dc:date>
    </item>
    <item>
      <title>Re: What will happen after splunk universal forwarder reached throughput limit</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-will-happen-after-splunk-universal-forwarder-reached/m-p/658350#M17422</link>
      <description>&lt;P&gt;If you have rights set up correctly (you should have as this is working after restart), I don’t see any reason why it’s didn’t work! I said that your next step is to create a support case (bug report) to splunk support to solve this issue.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2023 21:04:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-will-happen-after-splunk-universal-forwarder-reached/m-p/658350#M17422</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-09-21T21:04:23Z</dc:date>
    </item>
  </channel>
</rss>

