<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to speed Up Windows Event Log Processing? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-speed-Up-Windows-Event-Log-Processing/m-p/494414#M84409</link>
    <description>&lt;P&gt;I indexed about one GB of Windows Event Logs using the add data feature by monitoring the folder where the event log files are stored in. The indexing  takes about 12 hours to complete. I expected the process to be a lot faster. The CPU, Memory and Disk usage was constantly low during the processing. Is there a way to speed the processing up?&lt;/P&gt;</description>
    <pubDate>Wed, 27 Nov 2019 15:04:35 GMT</pubDate>
    <dc:creator>spiced</dc:creator>
    <dc:date>2019-11-27T15:04:35Z</dc:date>
    <item>
      <title>How to speed Up Windows Event Log Processing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-speed-Up-Windows-Event-Log-Processing/m-p/494414#M84409</link>
      <description>&lt;P&gt;I indexed about one GB of Windows Event Logs using the add data feature by monitoring the folder where the event log files are stored in. The indexing  takes about 12 hours to complete. I expected the process to be a lot faster. The CPU, Memory and Disk usage was constantly low during the processing. Is there a way to speed the processing up?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2019 15:04:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-speed-Up-Windows-Event-Log-Processing/m-p/494414#M84409</guid>
      <dc:creator>spiced</dc:creator>
      <dc:date>2019-11-27T15:04:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to speed Up Windows Event Log Processing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-speed-Up-Windows-Event-Log-Processing/m-p/494415#M84410</link>
      <description>&lt;P&gt;You probably have the default &lt;CODE&gt;maxKBps&lt;/CODE&gt; which I think is &lt;CODE&gt;1024&lt;/CODE&gt;.  Set this to &lt;CODE&gt;0&lt;/CODE&gt; in &lt;CODE&gt;limits.conf&lt;/CODE&gt; on your forwarders.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2019 16:39:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-speed-Up-Windows-Event-Log-Processing/m-p/494415#M84410</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-11-27T16:39:44Z</dc:date>
    </item>
  </channel>
</rss>

