<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there a way to change collection interval for HTTP Event Collector? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-change-collection-interval-for-HTTP-Event/m-p/339486#M62668</link>
    <description>&lt;P&gt;Where is the actual bottleneck on the heavy forwarder: network, memory, CPU?&lt;/P&gt;

&lt;P&gt;Forwarding to an indexer cluster should &lt;EM&gt;not&lt;/EM&gt; be slower than forwarding to a single indexer, so I am not surprised that didn't help.&lt;BR /&gt;
There is no "collection interval" on the heavy forwarder; it should be able to "collect" the events asynchronously as they are sent over http/https.&lt;/P&gt;

&lt;P&gt;My guess is that you may be exceeding the bandwidth of a single event collector. Have you considered using 2 heavy forwarders and having the sender switch between them?&lt;/P&gt;

&lt;P&gt;If the resources on the heavy forwarder are not being taxed, then perhaps the sender trying to exceed its output bandwidth.&lt;/P&gt;</description>
    <pubDate>Thu, 20 Apr 2017 06:22:10 GMT</pubDate>
    <dc:creator>lguinn2</dc:creator>
    <dc:date>2017-04-20T06:22:10Z</dc:date>
    <item>
      <title>Is there a way to change collection interval for HTTP Event Collector?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-change-collection-interval-for-HTTP-Event/m-p/339485#M62667</link>
      <description>&lt;P&gt;I am using HTTP Event Collector to collect Symantec ATP logs, my current ingest rate varies based on log size. It is typically around 2000-5000 logs at a rate of every 1 minute. My log source is generating between 1.5 M -3 M events per day. The collector is averaging about 480k-960k events per day. This is putting me into a logging deficit where I am unable to keep up with log generation. I am looking to change the interval to every 5 seconds or vastly increase the collection rate. I am for the most part default settings, the event collector is running on a heavy forwarder and forwarding to an indexer cluster, we have tried pointing to a single indexer but performance did not change.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2017 20:16:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-change-collection-interval-for-HTTP-Event/m-p/339485#M62667</guid>
      <dc:creator>splunkguy0342</dc:creator>
      <dc:date>2017-04-19T20:16:40Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to change collection interval for HTTP Event Collector?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-change-collection-interval-for-HTTP-Event/m-p/339486#M62668</link>
      <description>&lt;P&gt;Where is the actual bottleneck on the heavy forwarder: network, memory, CPU?&lt;/P&gt;

&lt;P&gt;Forwarding to an indexer cluster should &lt;EM&gt;not&lt;/EM&gt; be slower than forwarding to a single indexer, so I am not surprised that didn't help.&lt;BR /&gt;
There is no "collection interval" on the heavy forwarder; it should be able to "collect" the events asynchronously as they are sent over http/https.&lt;/P&gt;

&lt;P&gt;My guess is that you may be exceeding the bandwidth of a single event collector. Have you considered using 2 heavy forwarders and having the sender switch between them?&lt;/P&gt;

&lt;P&gt;If the resources on the heavy forwarder are not being taxed, then perhaps the sender trying to exceed its output bandwidth.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2017 06:22:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-change-collection-interval-for-HTTP-Event/m-p/339486#M62668</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2017-04-20T06:22:10Z</dc:date>
    </item>
  </channel>
</rss>

