<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: &amp;quot;ThruputProcessor - Current data throughput (259 kb/s) has reached maxKBps.&amp;quot; messages despite limits.conf file. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/quot-ThruputProcessor-Current-data-throughput-259-kb-s-has/m-p/102140#M21424</link>
    <description>&lt;P&gt;Hi Shephali,&lt;/P&gt;

&lt;P&gt;There are multiple possible reasons why this is not working:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;the option must be set under the &lt;CODE&gt;[thruput]&lt;/CODE&gt; stanza in &lt;CODE&gt;limits.conf&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;CODE&gt;btool&lt;/CODE&gt; does NOT actually show the config Splunk is using, it &lt;EM&gt;just&lt;/EM&gt; merges the on disk files and shows the potential config being used by Splunk&lt;/LI&gt;
&lt;LI&gt;to see the actual live config Splunk uses run &lt;CODE&gt;$SPLUNK_HOME/bin/splunk show config limits&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI&gt;check / verify file permissions&lt;/LI&gt;
&lt;LI&gt;last but not least it could be a bug?&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
    <pubDate>Mon, 28 Jan 2019 19:10:28 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2019-01-28T19:10:28Z</dc:date>
    <item>
      <title>"ThruputProcessor - Current data throughput (259 kb/s) has reached maxKBps." messages despite limits.conf file.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/quot-ThruputProcessor-Current-data-throughput-259-kb-s-has/m-p/102137#M21421</link>
      <description>&lt;P&gt;Hi everyone. I am receiving these messages on my forwarders:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;10-16-2013 18:38:59.118 +0000 INFO  ThruputProcessor - Current data throughput (259 kb/s) has reached maxKBps. As a result, data forwarding may be throttled. Consider increasing the value of maxKBps in limits.conf.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I actually have a limits.conf file deployed to all of my forwarders via an app. The contents of my limits.conf in the app/default directory are the following:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[thruput]
maxKBps = 0
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Is there any reason this would not be listened to?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2013 18:48:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/quot-ThruputProcessor-Current-data-throughput-259-kb-s-has/m-p/102137#M21421</guid>
      <dc:creator>msarro</dc:creator>
      <dc:date>2013-10-16T18:48:13Z</dc:date>
    </item>
    <item>
      <title>Re: "ThruputProcessor - Current data throughput (259 kb/s) has reached maxKBps." messages despite limits.conf file.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/quot-ThruputProcessor-Current-data-throughput-259-kb-s-has/m-p/102138#M21422</link>
      <description>&lt;P&gt;Hi msarro,&lt;/P&gt;

&lt;P&gt;you can run btool and see if your limits.conf gets applied &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;$SPLUNK_HOME/bin/splunk cmd btool limits list thruput
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;hope this helps ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2013 07:41:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/quot-ThruputProcessor-Current-data-throughput-259-kb-s-has/m-p/102138#M21422</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2013-10-17T07:41:23Z</dc:date>
    </item>
    <item>
      <title>Re: "ThruputProcessor - Current data throughput (259 kb/s) has reached maxKBps." messages despite limits.conf file.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/quot-ThruputProcessor-Current-data-throughput-259-kb-s-has/m-p/102139#M21423</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have a similar concern, where the maxKBps settings seem to be not getting applied.&lt;/P&gt;

&lt;P&gt;The  btool output on the UF is:&lt;BR /&gt;
$/opt/splunk/laa/splunkforwarder/bin/splunk btool limits list --debug | grep -i maxkbps&lt;BR /&gt;
/opt/splunk/laa/splunkforwarder/etc/apps/highoutput_forwarders/local/limits.conf maxKBps = 4096&lt;/P&gt;

&lt;P&gt;But still we receive messages like " Current data throughput (1024 kb/s) has reached maxKBps”  in the splunkd.log&lt;/P&gt;

&lt;P&gt;Any suggestions?&lt;BR /&gt;
Thanks in advance,&lt;BR /&gt;
Shephali&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 15:51:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/quot-ThruputProcessor-Current-data-throughput-259-kb-s-has/m-p/102139#M21423</guid>
      <dc:creator>Shephali</dc:creator>
      <dc:date>2019-01-18T15:51:34Z</dc:date>
    </item>
    <item>
      <title>Re: "ThruputProcessor - Current data throughput (259 kb/s) has reached maxKBps." messages despite limits.conf file.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/quot-ThruputProcessor-Current-data-throughput-259-kb-s-has/m-p/102140#M21424</link>
      <description>&lt;P&gt;Hi Shephali,&lt;/P&gt;

&lt;P&gt;There are multiple possible reasons why this is not working:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;the option must be set under the &lt;CODE&gt;[thruput]&lt;/CODE&gt; stanza in &lt;CODE&gt;limits.conf&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;CODE&gt;btool&lt;/CODE&gt; does NOT actually show the config Splunk is using, it &lt;EM&gt;just&lt;/EM&gt; merges the on disk files and shows the potential config being used by Splunk&lt;/LI&gt;
&lt;LI&gt;to see the actual live config Splunk uses run &lt;CODE&gt;$SPLUNK_HOME/bin/splunk show config limits&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI&gt;check / verify file permissions&lt;/LI&gt;
&lt;LI&gt;last but not least it could be a bug?&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jan 2019 19:10:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/quot-ThruputProcessor-Current-data-throughput-259-kb-s-has/m-p/102140#M21424</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2019-01-28T19:10:28Z</dc:date>
    </item>
  </channel>
</rss>

