<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic max throughputs of forwarders in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/max-throughputs-of-forwarders/m-p/71767#M14645</link>
    <description>&lt;P&gt;dear sirs,&lt;/P&gt;

&lt;P&gt;I'm aware about default limitations in a lightweight forwarder (256KB), which can be increased.
it’s also clear to me that this depends on a lot of points, like sources (local disk, lan mount, lan interface speed, system performance etc.) and functionality (raw, lightweight and full forwarder).&lt;/P&gt;

&lt;P&gt;what would be the critical throughput limit, that a forwarder could handle per second/minute/hour/day (practical experience) depending on functionality?&lt;/P&gt;

&lt;P&gt;the question is related to forwarders which could send a huge amount of data within a short time range.&lt;/P&gt;

&lt;P&gt;regards,
michael&lt;/P&gt;</description>
    <pubDate>Thu, 31 Mar 2011 14:38:44 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2011-03-31T14:38:44Z</dc:date>
    <item>
      <title>max throughputs of forwarders</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/max-throughputs-of-forwarders/m-p/71767#M14645</link>
      <description>&lt;P&gt;dear sirs,&lt;/P&gt;

&lt;P&gt;I'm aware about default limitations in a lightweight forwarder (256KB), which can be increased.
it’s also clear to me that this depends on a lot of points, like sources (local disk, lan mount, lan interface speed, system performance etc.) and functionality (raw, lightweight and full forwarder).&lt;/P&gt;

&lt;P&gt;what would be the critical throughput limit, that a forwarder could handle per second/minute/hour/day (practical experience) depending on functionality?&lt;/P&gt;

&lt;P&gt;the question is related to forwarders which could send a huge amount of data within a short time range.&lt;/P&gt;

&lt;P&gt;regards,
michael&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2011 14:38:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/max-throughputs-of-forwarders/m-p/71767#M14645</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2011-03-31T14:38:44Z</dc:date>
    </item>
    <item>
      <title>Re: max throughputs of forwarders</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/max-throughputs-of-forwarders/m-p/71768#M14646</link>
      <description>&lt;P&gt;had a little chat with &lt;EM&gt;mzorzi&lt;/EM&gt; and we came up with the conclusion, that the throughput limit for a forwarder would be the network interface. &lt;/P&gt;

&lt;P&gt;nevertheless, the indexer would be the bottleneck here, not the forwarder.&lt;/P&gt;

&lt;P&gt;regards&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2011 18:55:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/max-throughputs-of-forwarders/m-p/71768#M14646</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2011-04-05T18:55:42Z</dc:date>
    </item>
  </channel>
</rss>

