<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Data flood protection on forwarder or indexers in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Data-flood-protection-on-forwarder-or-indexers/m-p/56808#M11069</link>
    <description>&lt;P&gt;There currently is not, though it would be a very nice enhancement request. What you could do (relatively easily) is set yourself up a realtime alert to alert you if any forwarder send more than some amount of data in the past (say) 5 minutes. You would base this on the Splunk internal metrics log. If you look at the Splunk Deployment Monitor app, you can see examples of searches that do this on a dashboard, and you should be able to create alerts using those as a guide.&lt;/P&gt;</description>
    <pubDate>Thu, 11 Aug 2011 16:38:06 GMT</pubDate>
    <dc:creator>gkanapathy</dc:creator>
    <dc:date>2011-08-11T16:38:06Z</dc:date>
    <item>
      <title>Data flood protection on forwarder or indexers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-flood-protection-on-forwarder-or-indexers/m-p/56807#M11068</link>
      <description>&lt;P&gt;Our splunk universal forwarders may be configured by our customers in terms of logs they want to collect and transfer. An application that is logging very exessively could therefore drastically increase the amount of log data to be indexed. &lt;/P&gt;

&lt;P&gt;Is there some sort of flood protection available (on indexer or heavy forwarders) to detect universal forwarders that are transferring lots of data? Actions could be blacklisting the agent for a limited time period (and redirecting its log data to the nullqueue) or generating an alert or logging an error message.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Aug 2011 16:24:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-flood-protection-on-forwarder-or-indexers/m-p/56807#M11068</guid>
      <dc:creator>cwacha</dc:creator>
      <dc:date>2011-08-11T16:24:43Z</dc:date>
    </item>
    <item>
      <title>Re: Data flood protection on forwarder or indexers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-flood-protection-on-forwarder-or-indexers/m-p/56808#M11069</link>
      <description>&lt;P&gt;There currently is not, though it would be a very nice enhancement request. What you could do (relatively easily) is set yourself up a realtime alert to alert you if any forwarder send more than some amount of data in the past (say) 5 minutes. You would base this on the Splunk internal metrics log. If you look at the Splunk Deployment Monitor app, you can see examples of searches that do this on a dashboard, and you should be able to create alerts using those as a guide.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Aug 2011 16:38:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-flood-protection-on-forwarder-or-indexers/m-p/56808#M11069</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2011-08-11T16:38:06Z</dc:date>
    </item>
  </channel>
</rss>

