<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there a way to increase the maxQueueSize for Syslog output? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-increase-the-maxQueueSize-for-Syslog-output/m-p/134768#M27725</link>
    <description>&lt;P&gt;Your configuration option is wrong and needs to be on the outputs.conf configuration for the syslog.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;maxQueueSize = [&amp;lt;integer&amp;gt;|&amp;lt;integer&amp;gt;[KB|MB|GB]|auto]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;See:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.2/Admin/Outputsconf" target="test_blank"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.2/Admin/Outputsconf&lt;/A&gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 14 Apr 2015 19:42:56 GMT</pubDate>
    <dc:creator>alacercogitatus</dc:creator>
    <dc:date>2015-04-14T19:42:56Z</dc:date>
    <item>
      <title>Is there a way to increase the maxQueueSize for Syslog output?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-increase-the-maxQueueSize-for-Syslog-output/m-p/134767#M27724</link>
      <description>&lt;P&gt;Hello Splunkers,&lt;/P&gt;

&lt;P&gt;I would like to know if there is any way to increase the queue of my syslog group. I mean, currently I  forward logs that are received on my Splunk through a tierce solution on syslog and the default queue is 97 KB. Please find below an example :&lt;/P&gt;

&lt;P&gt;INFO Metrics - group=queue, name=my_syslog_group, max_size_kb=97, current_size_kb=0, current_size_kb=0, largest_size=0, smallest_size=0&lt;/P&gt;

&lt;P&gt;I tried to set up this configuration on server.conf :&lt;/P&gt;

&lt;P&gt;[queue]&lt;BR /&gt;
maxSize = 10MB&lt;/P&gt;

&lt;P&gt;[queue:my_syslog_group]&lt;BR /&gt;
maxSize = 10MB&lt;/P&gt;

&lt;P&gt;After restarting, I have always the default queue (97 KB). I saw nothing in the outputs.conf file to increase this queue for syslog output.&lt;/P&gt;

&lt;P&gt;Do you have any idea ?&lt;/P&gt;

&lt;P&gt;Thx for your help,&lt;/P&gt;

&lt;P&gt;Regards,&lt;/P&gt;

&lt;P&gt;Ludo&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:28:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-increase-the-maxQueueSize-for-Syslog-output/m-p/134767#M27724</guid>
      <dc:creator>ludoz13</dc:creator>
      <dc:date>2020-09-28T19:28:22Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to increase the maxQueueSize for Syslog output?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-increase-the-maxQueueSize-for-Syslog-output/m-p/134768#M27725</link>
      <description>&lt;P&gt;Your configuration option is wrong and needs to be on the outputs.conf configuration for the syslog.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;maxQueueSize = [&amp;lt;integer&amp;gt;|&amp;lt;integer&amp;gt;[KB|MB|GB]|auto]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;See:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.2/Admin/Outputsconf" target="test_blank"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.2/Admin/Outputsconf&lt;/A&gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 14 Apr 2015 19:42:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-increase-the-maxQueueSize-for-Syslog-output/m-p/134768#M27725</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2015-04-14T19:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to increase the maxQueueSize for Syslog output?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-increase-the-maxQueueSize-for-Syslog-output/m-p/134769#M27726</link>
      <description>&lt;P&gt;Hello alacercogitatus,&lt;/P&gt;

&lt;P&gt;Thanks for your answser but could you please confirm us that this option setting "maxQueueSize" is for Syslog output.&lt;/P&gt;

&lt;P&gt;I see on the documentation that this option is only for TCP output (splunk system)&lt;/P&gt;

&lt;P&gt;Thanks a lot,&lt;/P&gt;

&lt;P&gt;Regards,&lt;/P&gt;

&lt;P&gt;Ludo&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2015 20:01:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-increase-the-maxQueueSize-for-Syslog-output/m-p/134769#M27726</guid>
      <dc:creator>ludoz13</dc:creator>
      <dc:date>2015-04-14T20:01:02Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to increase the maxQueueSize for Syslog output?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-increase-the-maxQueueSize-for-Syslog-output/m-p/519887#M87900</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Did you find any solution for this? Unfortunately I cannot see any option to drop events when queue full for the syslog output processor&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2020 10:11:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-increase-the-maxQueueSize-for-Syslog-output/m-p/519887#M87900</guid>
      <dc:creator>harishmeetsu</dc:creator>
      <dc:date>2020-09-16T10:11:53Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to increase the maxQueueSize for Syslog output?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-increase-the-maxQueueSize-for-Syslog-output/m-p/527206#M88921</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Just wondering if anyone has been able to come up with a fix / work-around for this issue.&lt;/P&gt;&lt;P&gt;It's 5 yrs since it was originally asked and still it appears that the config options are very limited for this.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2020 05:04:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-increase-the-maxQueueSize-for-Syslog-output/m-p/527206#M88921</guid>
      <dc:creator>kozanic_mg</dc:creator>
      <dc:date>2020-10-30T05:04:38Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to increase the maxQueueSize for Syslog output?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-increase-the-maxQueueSize-for-Syslog-output/m-p/527218#M88923</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/169400"&gt;@harishmeetsu&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I had a problem few months ago related to this: i tried to enlarge the maxQueueSize and my system was blocked because the full syslog queue blocked all the other queues(I was working on an Heavy Forwarder).&lt;/P&gt;&lt;P&gt;I opened a case to Splunk Support and they gave me two solutions:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;using the parallel ingestion and add more resources to the system,&lt;/LI&gt;&lt;LI&gt;writing data in a file and using r-syslog.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I followed their first hint and I was able to send more data via syslog (around 20kb/s instead 1).&lt;/P&gt;&lt;P&gt;To do this, you have to add to your server.conf:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[general]
parallelIngestionPipelines = 2&lt;/LI-CODE&gt;&lt;P&gt;Before you ask: it isn't possible to use an higher value, I tried without results!&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2020 07:09:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-increase-the-maxQueueSize-for-Syslog-output/m-p/527218#M88923</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-10-30T07:09:28Z</dc:date>
    </item>
  </channel>
</rss>

