<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to limit heavy forwarder bandwidth in limits.conf? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-limit-heavy-forwarder-bandwidth-in-limits-conf/m-p/464665#M80115</link>
    <description>&lt;P&gt;Hi @realsplunk,&lt;BR /&gt;
yes it's the same thing, only one hint beware to the traffic to avoid that your HF will be the bottle neck of your network.&lt;/P&gt;

&lt;P&gt;Ciao.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
    <pubDate>Mon, 25 May 2020 14:22:04 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2020-05-25T14:22:04Z</dc:date>
    <item>
      <title>How to limit heavy forwarder bandwidth in limits.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-limit-heavy-forwarder-bandwidth-in-limits-conf/m-p/464664#M80114</link>
      <description>&lt;P&gt;Hello guys,&lt;/P&gt;
&lt;P&gt;is it possible to limit Heavy forwarders bandwidth like UF (setting [thruput] in &lt;CODE&gt;limits.conf&lt;/CODE&gt; for forwarders)?&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jun 2020 01:28:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-limit-heavy-forwarder-bandwidth-in-limits-conf/m-p/464664#M80114</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2020-06-07T01:28:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit heavy forwarder bandwidth in limits.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-limit-heavy-forwarder-bandwidth-in-limits-conf/m-p/464665#M80115</link>
      <description>&lt;P&gt;Hi @realsplunk,&lt;BR /&gt;
yes it's the same thing, only one hint beware to the traffic to avoid that your HF will be the bottle neck of your network.&lt;/P&gt;

&lt;P&gt;Ciao.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 25 May 2020 14:22:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-limit-heavy-forwarder-bandwidth-in-limits-conf/m-p/464665#M80115</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-05-25T14:22:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit heavy forwarder bandwidth in limits.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-limit-heavy-forwarder-bandwidth-in-limits-conf/m-p/464666#M80116</link>
      <description>&lt;P&gt;Hi Cusello,&lt;BR /&gt;
we have +800 KB/s indexing Checkpoint through OPSEC app and other syslogs through tcp/udp basically.&lt;/P&gt;

&lt;P&gt;Here are the confs :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[root@HFSIEM01 ~]# grep -r -i maxKBps /OPT/siem/splunk/etc
/OPT/siem/splunk/etc/system/README/server.conf.spec:    1. maxKBps (in limits.conf)
/OPT/siem/splunk/etc/system/README/limits.conf.spec:maxKBps = &amp;lt;integer&amp;gt;
/OPT/siem/splunk/etc/system/README/limits.conf.spec:  * The thruput processor applies the 'maxKBps' setting for each
/OPT/siem/splunk/etc/system/README/limits.conf.spec:    pipelines, the processor multiplies the 'maxKBps' value

/OPT/siem/splunk/etc/system/default/limits.conf:maxKBps = 0
/OPT/siem/splunk/etc/apps/SplunkLightForwarder/default/limits.conf:maxKBps = 256
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If I understand conf file precedence and if it applied, the limit should be 256?    &lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 25 May 2020 15:10:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-limit-heavy-forwarder-bandwidth-in-limits-conf/m-p/464666#M80116</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2020-05-25T15:10:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit heavy forwarder bandwidth in limits.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-limit-heavy-forwarder-bandwidth-in-limits-conf/m-p/464667#M80117</link>
      <description>&lt;P&gt;From support : "Splunk Heavy Forwarder does not have setting to limit network bandwidth."&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2020 14:26:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-limit-heavy-forwarder-bandwidth-in-limits-conf/m-p/464667#M80117</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2020-05-26T14:26:03Z</dc:date>
    </item>
  </channel>
</rss>

