<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Will the HTTP Event Collector respond with any error if it can't keep up with event volume? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Will-the-HTTP-Event-Collector-respond-with-any-error-if-it-can-t/m-p/230810#M44940</link>
    <description>&lt;P&gt;@ineeman&lt;BR /&gt;
How should we make sure that we don't hit this issue? I keep getting this 503 Server busy error when I have seen a large volume of events getting posted to HEC.&lt;/P&gt;

&lt;P&gt;Thanks much!&lt;/P&gt;</description>
    <pubDate>Mon, 05 Feb 2018 18:36:32 GMT</pubDate>
    <dc:creator>gaarti</dc:creator>
    <dc:date>2018-02-05T18:36:32Z</dc:date>
    <item>
      <title>Will the HTTP Event Collector respond with any error if it can't keep up with event volume?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Will-the-HTTP-Event-Collector-respond-with-any-error-if-it-can-t/m-p/230808#M44938</link>
      <description>&lt;P&gt;I am planning to use HEC on heavy forwarder(s) which will forward to the indexer(s). &lt;/P&gt;

&lt;P&gt;My question:  Is HEC designed to return any error(s) to the sender if it can't keep up with volume of input?  Does in-memory input queue configuration have any impact on response?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 23:55:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Will-the-HTTP-Event-Collector-respond-with-any-error-if-it-can-t/m-p/230808#M44938</guid>
      <dc:creator>sandeep23</dc:creator>
      <dc:date>2016-08-16T23:55:59Z</dc:date>
    </item>
    <item>
      <title>Re: Will the HTTP Event Collector respond with any error if it can't keep up with event volume?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Will-the-HTTP-Event-Collector-respond-with-any-error-if-it-can-t/m-p/230809#M44939</link>
      <description>&lt;P&gt;Yes - if we fail to enqueue events into the queues (in memory or persistent) we will give you back an error (and a 502 response code) to say the service is too busy to handle requests.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2016 00:26:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Will-the-HTTP-Event-Collector-respond-with-any-error-if-it-can-t/m-p/230809#M44939</guid>
      <dc:creator>ineeman</dc:creator>
      <dc:date>2016-08-17T00:26:37Z</dc:date>
    </item>
    <item>
      <title>Re: Will the HTTP Event Collector respond with any error if it can't keep up with event volume?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Will-the-HTTP-Event-Collector-respond-with-any-error-if-it-can-t/m-p/230810#M44940</link>
      <description>&lt;P&gt;@ineeman&lt;BR /&gt;
How should we make sure that we don't hit this issue? I keep getting this 503 Server busy error when I have seen a large volume of events getting posted to HEC.&lt;/P&gt;

&lt;P&gt;Thanks much!&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2018 18:36:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Will-the-HTTP-Event-Collector-respond-with-any-error-if-it-can-t/m-p/230810#M44940</guid>
      <dc:creator>gaarti</dc:creator>
      <dc:date>2018-02-05T18:36:32Z</dc:date>
    </item>
  </channel>
</rss>

