<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Metrics.log - some information! in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Metrics-log-some-information/m-p/671727#M18113</link>
    <description>&lt;P&gt;Hi.&lt;BR /&gt;I use a lot the metrics.log Indexer side, to debug some bottleneck and/or stress inside the Infrastructure.&lt;/P&gt;&lt;P&gt;There is a field, i can't really understand at all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;INFO  Metrics - group=tcpin_connections
x.x.x.x:50496:9997
connectionType=cookedSSL
sourcePort=50496
sourceHost=x.x.x.x
sourceIp=x.x.x.x
destPort=9997
kb=15.458984375
_tcp_avg_thruput=7.262044477222557
_tcp_Kprocessed=589.84765625
[...]&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's the "&lt;STRONG&gt;&lt;EM&gt;tcp_Kprocessed"&lt;/EM&gt; &lt;/STRONG&gt;field,&lt;BR /&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;especially related to the field&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt; "&lt;EM&gt;&lt;STRONG&gt;kb&lt;/STRONG&gt;&lt;/EM&gt;", which is &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;the most important, in my opinion&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;What is in practice "&lt;STRONG&gt;&lt;EM&gt;tcp_Kprocessed&lt;/EM&gt;&lt;/STRONG&gt;", considering that its values are often very inconsistent and not proportionate to the kb?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Wed, 13 Dec 2023 13:38:23 GMT</pubDate>
    <dc:creator>verbal_666</dc:creator>
    <dc:date>2023-12-13T13:38:23Z</dc:date>
    <item>
      <title>Metrics.log - some information!</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Metrics-log-some-information/m-p/671727#M18113</link>
      <description>&lt;P&gt;Hi.&lt;BR /&gt;I use a lot the metrics.log Indexer side, to debug some bottleneck and/or stress inside the Infrastructure.&lt;/P&gt;&lt;P&gt;There is a field, i can't really understand at all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;INFO  Metrics - group=tcpin_connections
x.x.x.x:50496:9997
connectionType=cookedSSL
sourcePort=50496
sourceHost=x.x.x.x
sourceIp=x.x.x.x
destPort=9997
kb=15.458984375
_tcp_avg_thruput=7.262044477222557
_tcp_Kprocessed=589.84765625
[...]&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's the "&lt;STRONG&gt;&lt;EM&gt;tcp_Kprocessed"&lt;/EM&gt; &lt;/STRONG&gt;field,&lt;BR /&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;especially related to the field&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt; "&lt;EM&gt;&lt;STRONG&gt;kb&lt;/STRONG&gt;&lt;/EM&gt;", which is &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;the most important, in my opinion&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;What is in practice "&lt;STRONG&gt;&lt;EM&gt;tcp_Kprocessed&lt;/EM&gt;&lt;/STRONG&gt;", considering that its values are often very inconsistent and not proportionate to the kb?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 13:38:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Metrics-log-some-information/m-p/671727#M18113</guid>
      <dc:creator>verbal_666</dc:creator>
      <dc:date>2023-12-13T13:38:23Z</dc:date>
    </item>
    <item>
      <title>Re: Metrics.log - some information!</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Metrics-log-some-information/m-p/672033#M18142</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/28550"&gt;@verbal_666&lt;/a&gt;&amp;nbsp; I think this is the volume indexed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2023 14:23:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Metrics-log-some-information/m-p/672033#M18142</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2023-12-15T14:23:13Z</dc:date>
    </item>
    <item>
      <title>Re: Metrics.log - some information!</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Metrics-log-some-information/m-p/672035#M18143</link>
      <description>&lt;P&gt;I'm counting the "&lt;STRONG&gt;&lt;EM&gt;kb&lt;/EM&gt;&lt;/STRONG&gt;" as volume of data received and ingected into Indexers.&lt;BR /&gt;Is this wrong, so?&lt;/P&gt;&lt;P&gt;So, what's the relation beetwen "&lt;EM&gt;&lt;STRONG&gt;kb&lt;/STRONG&gt;&lt;/EM&gt;" and "&lt;STRONG&gt;&lt;EM&gt;tcp_Kprocessed&lt;/EM&gt;&lt;/STRONG&gt;" ?&lt;/P&gt;&lt;P&gt;I'm still in doubt &lt;span class="lia-unicode-emoji" title=":thinking_face:"&gt;🤔&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":thinking_face:"&gt;🤔&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":thinking_face:"&gt;🤔&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2023 14:35:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Metrics-log-some-information/m-p/672035#M18143</guid>
      <dc:creator>verbal_666</dc:creator>
      <dc:date>2023-12-15T14:35:43Z</dc:date>
    </item>
    <item>
      <title>Re: Metrics.log - some information!</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Metrics-log-some-information/m-p/672037#M18144</link>
      <description>&lt;P&gt;Seems tcp_kprocessed is total&amp;nbsp;&lt;SPAN&gt;transferred data and kb the volume indexed for that particular event.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You may submit support ticket for further information as this doesn't look documented.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2023 14:41:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Metrics-log-some-information/m-p/672037#M18144</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2023-12-15T14:41:21Z</dc:date>
    </item>
    <item>
      <title>Re: Metrics.log - some information!</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Metrics-log-some-information/m-p/672038#M18145</link>
      <description>&lt;P&gt;Maybe could be&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;tcp_Kprocessed&lt;/EM&gt;&lt;/STRONG&gt; == Kb received by the receiver as a packet of events&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;kb&lt;/EM&gt;&lt;/STRONG&gt; == the real Kb (compressed) written on Indexer storage&lt;/P&gt;&lt;P&gt;So, for my purposes, i keep on using the sum of "&lt;STRONG&gt;&lt;EM&gt;kb&lt;/EM&gt;&lt;/STRONG&gt;" as volume of data from UF to Indexers.&lt;/P&gt;&lt;P&gt;Yes, it's not documented at all &lt;span class="lia-unicode-emoji" title=":face_with_rolling_eyes:"&gt;🙄&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":face_with_rolling_eyes:"&gt;🙄&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":face_with_rolling_eyes:"&gt;🙄&lt;/span&gt;🤷‍&lt;span class="lia-unicode-emoji" title=":male_sign:"&gt;♂️&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2023 14:47:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Metrics-log-some-information/m-p/672038#M18145</guid>
      <dc:creator>verbal_666</dc:creator>
      <dc:date>2023-12-15T14:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: Metrics.log - some information!</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Metrics-log-some-information/m-p/672039#M18146</link>
      <description>&lt;P&gt;yes, sounds logic &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;You can add idea to document these fields at&amp;nbsp;&lt;A href="https://ideas.splunk.com/ideas/new" target="_blank"&gt;https://ideas.splunk.com/ideas/new&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2023 14:49:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Metrics-log-some-information/m-p/672039#M18146</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2023-12-15T14:49:03Z</dc:date>
    </item>
    <item>
      <title>Re: Metrics.log - some information!</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Metrics-log-some-information/m-p/672096#M18148</link>
      <description>&lt;P&gt;Yep!&lt;/P&gt;&lt;P&gt;Le't stay as said... if someone else wants to add something, you're welcome,&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;tcp_Kprocessed&lt;/EM&gt;&lt;/STRONG&gt; == Kb received by the receiver as a packet of events&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;kb&lt;/EM&gt;&lt;/STRONG&gt; == the real Kb (compressed) written on Indexer storage&lt;/P&gt;&lt;P&gt;Explicit and simple,&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;tcp_Kprocessed&lt;/EM&gt;&lt;/STRONG&gt; == the Networking thruput of events packet&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;kb&lt;/EM&gt;&lt;/STRONG&gt; == the Compressed Data written to Indexer Storage of previous packet&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Dec 2023 08:04:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Metrics-log-some-information/m-p/672096#M18148</guid>
      <dc:creator>verbal_666</dc:creator>
      <dc:date>2023-12-16T08:04:51Z</dc:date>
    </item>
  </channel>
</rss>

