<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: The aggqueue and parsingqueue consistently full / blocked - how do I increase ? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/The-aggqueue-and-parsingqueue-consistently-full-blocked-how-do-I/m-p/11083#M507</link>
    <description>&lt;P&gt;Indexing is very slow - added 250 mb to indices - helped some - going to the customized time stamping formats next due to mixed windows, sourcefire, and cisco data - everything is single line coming from snare and syslog so will turn on Should_linemerge = false - regexes are spot on .. and only as long as I need to pull fields from .. thanks for the help will check back. - What is the pulldown value all about - noticed it in the props.conf in default - should it be added to the local props.conf ?&lt;/P&gt;</description>
    <pubDate>Thu, 08 Apr 2010 01:52:16 GMT</pubDate>
    <dc:creator>MikeyG</dc:creator>
    <dc:date>2010-04-08T01:52:16Z</dc:date>
    <item>
      <title>The aggqueue and parsingqueue consistently full / blocked - how do I increase ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/The-aggqueue-and-parsingqueue-consistently-full-blocked-how-do-I/m-p/11081#M505</link>
      <description>&lt;P&gt;Search is index="_internal" source="*metrics.log" group="queue" | timechart perc90(current_size) by name&lt;/P&gt;

&lt;P&gt;Results are:&lt;/P&gt;

&lt;P&gt;group=queue, name=parsingqueue, blocked!!=true, max_size=1000, filled_count=15, empty_count=0, current_size=1000, largest_size=1000, smallest_size=996&lt;/P&gt;

&lt;P&gt;group=queue, name=aggqueue, blocked!!=true, max_size=1000, filled_count=31, empty_count=0, current_size=1000, largest_size=1000, smallest_size=930&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2010 22:42:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/The-aggqueue-and-parsingqueue-consistently-full-blocked-how-do-I/m-p/11081#M505</guid>
      <dc:creator>MikeyG</dc:creator>
      <dc:date>2010-04-07T22:42:14Z</dc:date>
    </item>
    <item>
      <title>Re: The aggqueue and parsingqueue consistently full / blocked - how do I increase ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/The-aggqueue-and-parsingqueue-consistently-full-blocked-how-do-I/m-p/11082#M506</link>
      <description>&lt;P&gt;Are you actually experiencing problems with indexing throughput? &lt;/P&gt;

&lt;P&gt;Increasing the length of the queue will probably not help. A constantly filled queue indicates that the processing that takes place on it is unable to keep up with the incoming work. Increasing the queue may give you a little room if this happens because your data comes in small bursts. If you are not experiencing indexing throughput problems, there's nothing you need to do.&lt;/P&gt;

&lt;P&gt;If you &lt;EM&gt;are&lt;/EM&gt; experiencing indexing throughput problems, there are a few options. Among them:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Add another indexer&lt;/LI&gt;
&lt;LI&gt;Optimize any index-time props and transforms rules on your data, or remove unnecessary ones. These include:
&lt;UL&gt;
&lt;LI&gt;Timestamp extraction. If you can specify explicit timestams formats, those are than having Splunk guess&lt;/LI&gt;
&lt;LI&gt;Line merging rules. If your data is always single line, you can set SHOULD_LINEMERGE = false. You can also consider using custom LINE_BREAKER settings instead of line merging rules for multi-line data.&lt;/LI&gt;
&lt;LI&gt;Number and efficiency of any regexes used in TRANSFORMS and SEDCMD rules&lt;/LI&gt;
&lt;/UL&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 08 Apr 2010 01:02:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/The-aggqueue-and-parsingqueue-consistently-full-blocked-how-do-I/m-p/11082#M506</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-04-08T01:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: The aggqueue and parsingqueue consistently full / blocked - how do I increase ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/The-aggqueue-and-parsingqueue-consistently-full-blocked-how-do-I/m-p/11083#M507</link>
      <description>&lt;P&gt;Indexing is very slow - added 250 mb to indices - helped some - going to the customized time stamping formats next due to mixed windows, sourcefire, and cisco data - everything is single line coming from snare and syslog so will turn on Should_linemerge = false - regexes are spot on .. and only as long as I need to pull fields from .. thanks for the help will check back. - What is the pulldown value all about - noticed it in the props.conf in default - should it be added to the local props.conf ?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Apr 2010 01:52:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/The-aggqueue-and-parsingqueue-consistently-full-blocked-how-do-I/m-p/11083#M507</guid>
      <dc:creator>MikeyG</dc:creator>
      <dc:date>2010-04-08T01:52:16Z</dc:date>
    </item>
    <item>
      <title>Re: The aggqueue and parsingqueue consistently full / blocked - how do I increase ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/The-aggqueue-and-parsingqueue-consistently-full-blocked-how-do-I/m-p/11084#M508</link>
      <description>&lt;P&gt;you can ignore pulldown. It just controls whether the sourcetype appears in the GUI list. the other problem may just be that you need a faster machine or faster disk.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Apr 2010 03:21:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/The-aggqueue-and-parsingqueue-consistently-full-blocked-how-do-I/m-p/11084#M508</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-04-08T03:21:23Z</dc:date>
    </item>
  </channel>
</rss>

