<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Need assistance getting large data into Splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Need-assistance-getting-large-data-into-Splunk/m-p/509718#M86693</link>
    <description>&lt;P&gt;This is a note my client sent:&lt;/P&gt;&lt;P&gt;I can’t really use the logs from Splunk, because they are spotty.. Think I figured out why it’s missing data though.&amp;nbsp; From our last meeting, they bumped up the transfer rate from 1024KBps to 2048KBps because the CE was generating too much data.&amp;nbsp; However, the CE raw logs generate roughly about 75MB/Minute or 1.25MBps raw.&amp;nbsp; Since Splunk does use compression at ~17%, the 2KBps gets you about 11KBps raw.&amp;nbsp; The 1.25MBps is roughly 217.6KBps compressed.&amp;nbsp; Hence, it gives you roughly 5% of the total logs.&amp;nbsp; To support Openway and prevent dropping any logs, we need to set a conservative rate to handle 110MB/minute raw, which would be ~319KBps.&lt;/P&gt;&lt;P&gt;We did set in the limits.conf to the 2048 mentioned above, but we're not certain how to set to a level the client needs.&lt;/P&gt;</description>
    <pubDate>Fri, 17 Jul 2020 14:18:52 GMT</pubDate>
    <dc:creator>nls7010</dc:creator>
    <dc:date>2020-07-17T14:18:52Z</dc:date>
    <item>
      <title>Need assistance getting large data into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-assistance-getting-large-data-into-Splunk/m-p/509718#M86693</link>
      <description>&lt;P&gt;This is a note my client sent:&lt;/P&gt;&lt;P&gt;I can’t really use the logs from Splunk, because they are spotty.. Think I figured out why it’s missing data though.&amp;nbsp; From our last meeting, they bumped up the transfer rate from 1024KBps to 2048KBps because the CE was generating too much data.&amp;nbsp; However, the CE raw logs generate roughly about 75MB/Minute or 1.25MBps raw.&amp;nbsp; Since Splunk does use compression at ~17%, the 2KBps gets you about 11KBps raw.&amp;nbsp; The 1.25MBps is roughly 217.6KBps compressed.&amp;nbsp; Hence, it gives you roughly 5% of the total logs.&amp;nbsp; To support Openway and prevent dropping any logs, we need to set a conservative rate to handle 110MB/minute raw, which would be ~319KBps.&lt;/P&gt;&lt;P&gt;We did set in the limits.conf to the 2048 mentioned above, but we're not certain how to set to a level the client needs.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2020 14:18:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-assistance-getting-large-data-into-Splunk/m-p/509718#M86693</guid>
      <dc:creator>nls7010</dc:creator>
      <dc:date>2020-07-17T14:18:52Z</dc:date>
    </item>
  </channel>
</rss>

