<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is it best practice to collect data from network drives using a heavy forwarder? I'm seeing performance issues. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-best-practice-to-collect-data-from-network-drives-using-a/m-p/226751#M44276</link>
    <description>&lt;P&gt;I started seeing massive delays (5+ minutes, sometimes 10) after upgrading to 6.3.0 (Also having this problem is 6.3.1). I have about 60 UNC paths that I'm monitoring.&lt;/P&gt;

&lt;P&gt;Changing to use the Universal Forwarder on the source of the logs worked around the massive delay problem for us,&lt;/P&gt;</description>
    <pubDate>Fri, 13 Nov 2015 18:04:27 GMT</pubDate>
    <dc:creator>JeffSchumacher</dc:creator>
    <dc:date>2015-11-13T18:04:27Z</dc:date>
    <item>
      <title>Is it best practice to collect data from network drives using a heavy forwarder? I'm seeing performance issues.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-best-practice-to-collect-data-from-network-drives-using-a/m-p/226750#M44275</link>
      <description>&lt;P&gt;Hello and good morning,&lt;/P&gt;

&lt;P&gt;I have a heavy forwarder that takes inputs from several network drives and it's working fine so far.&lt;/P&gt;

&lt;P&gt;The question I can't find an answer to in the Splunk docs is, is getting data from network drives best practice?&lt;/P&gt;

&lt;P&gt;The thing is, I have performance problems. The data is indexed with a delay and I'm trying to figure out if maybe the network drives have a part in that.&lt;/P&gt;

&lt;P&gt;Any assistance on this would be greatly appreciated. A link to a Splunk doc would be perfect.&lt;/P&gt;

&lt;P&gt;Thank you &lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2015 08:01:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-best-practice-to-collect-data-from-network-drives-using-a/m-p/226750#M44275</guid>
      <dc:creator>dkeck</dc:creator>
      <dc:date>2015-11-13T08:01:48Z</dc:date>
    </item>
    <item>
      <title>Re: Is it best practice to collect data from network drives using a heavy forwarder? I'm seeing performance issues.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-best-practice-to-collect-data-from-network-drives-using-a/m-p/226751#M44276</link>
      <description>&lt;P&gt;I started seeing massive delays (5+ minutes, sometimes 10) after upgrading to 6.3.0 (Also having this problem is 6.3.1). I have about 60 UNC paths that I'm monitoring.&lt;/P&gt;

&lt;P&gt;Changing to use the Universal Forwarder on the source of the logs worked around the massive delay problem for us,&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2015 18:04:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-best-practice-to-collect-data-from-network-drives-using-a/m-p/226751#M44276</guid>
      <dc:creator>JeffSchumacher</dc:creator>
      <dc:date>2015-11-13T18:04:27Z</dc:date>
    </item>
    <item>
      <title>Re: Is it best practice to collect data from network drives using a heavy forwarder? I'm seeing performance issues.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-best-practice-to-collect-data-from-network-drives-using-a/m-p/226752#M44277</link>
      <description>&lt;P&gt;Thank you &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;I found a different failure, repsonsible for the delay. Thank you very much anyway.&lt;/P&gt;

&lt;P&gt;Several Servers in the outputs.conf where not reachable, so splunk retried all the time.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Nov 2015 06:46:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-best-practice-to-collect-data-from-network-drives-using-a/m-p/226752#M44277</guid>
      <dc:creator>dkeck</dc:creator>
      <dc:date>2015-11-16T06:46:50Z</dc:date>
    </item>
    <item>
      <title>Re: Is it best practice to collect data from network drives using a heavy forwarder? I'm seeing performance issues.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-best-practice-to-collect-data-from-network-drives-using-a/m-p/226753#M44278</link>
      <description>&lt;P&gt;I would like to except your answer..but theres not button for it...sry&lt;/P&gt;</description>
      <pubDate>Mon, 16 Nov 2015 06:54:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-best-practice-to-collect-data-from-network-drives-using-a/m-p/226753#M44278</guid>
      <dc:creator>dkeck</dc:creator>
      <dc:date>2015-11-16T06:54:09Z</dc:date>
    </item>
  </channel>
</rss>

