<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Indexer queue sizes in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-queue-sizes/m-p/678343#M113355</link>
    <description>&lt;P&gt;AFAIK, indexer queues are not configurable.&amp;nbsp; You can, however, use maxQueueSize in outputs.conf on the forwarders to set the size of the output queue.&amp;nbsp; That's the queue where packets are stored if the destination becomes unavailable.&lt;/P&gt;&lt;P&gt;In the case of HEC inputs, it's the responsibility of the client to retry any request that gets a non-200 (OK) response code ("server is busy" in this case).&lt;/P&gt;</description>
    <pubDate>Thu, 22 Feb 2024 14:39:12 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2024-02-22T14:39:12Z</dc:date>
    <item>
      <title>Indexer queue sizes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-queue-sizes/m-p/678079#M113325</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;We have been facing some errors with Splunk indexers, where it says something like below.&lt;/P&gt;&lt;P&gt;```&lt;/P&gt;&lt;P&gt;Failed processing http input, token name=&amp;lt;HECtoken&amp;gt;, channel=n/a, source_IP=, reply=9, events_processed=62, http_input_body_size=47326, parsing_err="Server is busy"&lt;/P&gt;&lt;P&gt;```&lt;/P&gt;&lt;P&gt;And I found in some discussions that increasing queue sizes may help sometimes. We are indexing ~400GB per day and it makes sense to increase the queue sizes as default values might not be good enough in this case.&lt;/P&gt;&lt;P&gt;However, the splunk docs doesnt have a detailed explanation of which queues can be set in server.conf and what are the proportions that we need consider. Can someone help with understanding this?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2024 14:07:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-queue-sizes/m-p/678079#M113325</guid>
      <dc:creator>jpillai</dc:creator>
      <dc:date>2024-02-20T14:07:14Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer queue sizes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-queue-sizes/m-p/678343#M113355</link>
      <description>&lt;P&gt;AFAIK, indexer queues are not configurable.&amp;nbsp; You can, however, use maxQueueSize in outputs.conf on the forwarders to set the size of the output queue.&amp;nbsp; That's the queue where packets are stored if the destination becomes unavailable.&lt;/P&gt;&lt;P&gt;In the case of HEC inputs, it's the responsibility of the client to retry any request that gets a non-200 (OK) response code ("server is busy" in this case).&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 14:39:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-queue-sizes/m-p/678343#M113355</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-02-22T14:39:12Z</dc:date>
    </item>
  </channel>
</rss>

