<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Make the throughput variable in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-Make-the-throughput-variable/m-p/601934#M104862</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/245432"&gt;@AntoineDRN&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;no, when you set a parameter it's settend until the next modification and restart.&lt;/P&gt;&lt;P&gt;for ths reason, I usually use the default parameters until I see some queue problem.&lt;/P&gt;&lt;P&gt;If there are queue issues I modify the referring parameter.&lt;/P&gt;&lt;P&gt;Anyway, Splunk automatical manage queues, the only issue is that you could have a delay in data indexing so you have to configure your alerts to consider this possible delay, e.g. if you found a delay of 5 minutes on your data, instead taking in an alert the last 5 minutes, you could take earliest=-15m@m and latest=-10m@m to be sure to have all the data.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Wed, 15 Jun 2022 15:29:19 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2022-06-15T15:29:19Z</dc:date>
    <item>
      <title>Is there a way to Make the throughput variable?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-Make-the-throughput-variable/m-p/601927#M104861</link>
      <description>&lt;P&gt;Hello Splunkers,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After my own unsuccessful researches, I thought you may have the answer.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, I'm wondering if there is a way to make the thruput variable.&lt;/P&gt;
&lt;P&gt;Indeed,&amp;nbsp; my search peer may have a too large amount of data to index at a time due to a network issue, and I would like to spread out the indexing during the night for example.&lt;/P&gt;
&lt;P&gt;So is there a way to set a throughput ([thruput]) limit when my server is the most asked and unset this limit when it is less used?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance for your time and your answer!&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Antoine&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2022 19:17:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-Make-the-throughput-variable/m-p/601927#M104861</guid>
      <dc:creator>AntoineDRN</dc:creator>
      <dc:date>2022-06-15T19:17:21Z</dc:date>
    </item>
    <item>
      <title>Re: Make the throughput variable</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-Make-the-throughput-variable/m-p/601934#M104862</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/245432"&gt;@AntoineDRN&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;no, when you set a parameter it's settend until the next modification and restart.&lt;/P&gt;&lt;P&gt;for ths reason, I usually use the default parameters until I see some queue problem.&lt;/P&gt;&lt;P&gt;If there are queue issues I modify the referring parameter.&lt;/P&gt;&lt;P&gt;Anyway, Splunk automatical manage queues, the only issue is that you could have a delay in data indexing so you have to configure your alerts to consider this possible delay, e.g. if you found a delay of 5 minutes on your data, instead taking in an alert the last 5 minutes, you could take earliest=-15m@m and latest=-10m@m to be sure to have all the data.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2022 15:29:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-Make-the-throughput-variable/m-p/601934#M104862</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-06-15T15:29:19Z</dc:date>
    </item>
    <item>
      <title>Re: Make the throughput variable</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-Make-the-throughput-variable/m-p/601935#M104863</link>
      <description>&lt;P&gt;Thanks for your answer, I'm gonna deal with it then.&lt;/P&gt;&lt;P&gt;To go further, does an index parallelization or maybe add one or more search peers can avoid or at least reduce the impact of a sudden large amount of data incoming?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2022 15:34:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-Make-the-throughput-variable/m-p/601935#M104863</guid>
      <dc:creator>AntoineDRN</dc:creator>
      <dc:date>2022-06-15T15:34:52Z</dc:date>
    </item>
    <item>
      <title>Re: Make the throughput variable</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-Make-the-throughput-variable/m-p/601937#M104864</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/245432"&gt;@AntoineDRN&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you should analyze the data flow, consider that a normally dimensioned Indexer (12 CPUs and 12 GB RAM) can manage searches and ingest until 150-200 GB/day (if you haven't ES or ITSI).&lt;/P&gt;&lt;P&gt;Obviously it depends on the peak moments and on the concurrent searches.&lt;/P&gt;&lt;P&gt;Anyway adding another search peer (Indexer) or giving more resulrces (CPUs) to the actual server surely will help.&lt;/P&gt;&lt;P&gt;Another bottleneck could be the storage: what's the throughput of your storage?&lt;/P&gt;&lt;P&gt;remember that Splunk requires for Hot Buckets at least 800 IOPS, that means many 15k or SSD disks and never use of SAN or NTFS (use them only for Cold buckets).&lt;/P&gt;&lt;P&gt;Anyway, see at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.6/Capacity/Referencehardware" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.6/Capacity/Referencehardware&lt;/A&gt;&amp;nbsp;to have all the hardware reference informations.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2022 15:45:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-Make-the-throughput-variable/m-p/601937#M104864</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-06-15T15:45:33Z</dc:date>
    </item>
    <item>
      <title>Re: Make the throughput variable</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-Make-the-throughput-variable/m-p/601941#M104865</link>
      <description>&lt;P&gt;Normally, the architecture have been set up for this kind of need. There is just a few edge cases like this one that might reveal problems.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will investigate further on the storages throughput and the hardware requirement.&lt;/P&gt;&lt;P&gt;Thanks again for your help,&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Antoine&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2022 16:09:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-Make-the-throughput-variable/m-p/601941#M104865</guid>
      <dc:creator>AntoineDRN</dc:creator>
      <dc:date>2022-06-15T16:09:07Z</dc:date>
    </item>
    <item>
      <title>Re: Make the throughput variable</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-Make-the-throughput-variable/m-p/601942#M104866</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/245432"&gt;@AntoineDRN&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Please accept one answer for the other people of Community&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2022 16:11:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-Make-the-throughput-variable/m-p/601942#M104866</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-06-15T16:11:29Z</dc:date>
    </item>
  </channel>
</rss>

