<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk indexing delay in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Splunk-indexing-delay/m-p/536809#M7087</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222802"&gt;@rahul2gupta&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;maxKBps=0 means unlimited, there is no need to change.&lt;/P&gt;&lt;P&gt;Can you check internal logs if you see an error on TailReader component like File Descriptor Cache Full?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal host=aeaxxxx component=TailReader&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If there are too many files monitored, UF cannot monitor all, that may cause delays.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 22 Jan 2021 09:54:29 GMT</pubDate>
    <dc:creator>scelikok</dc:creator>
    <dc:date>2021-01-22T09:54:29Z</dc:date>
    <item>
      <title>Splunk indexing delay</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-indexing-delay/m-p/536615#M7080</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We've observed slow Splunk indexing in one webMethods servers (aexxxxxx) causing certain testcases to fail.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Normally indexing completes in 1-2 seconds. But on some servers it takes much longer (upto 2 minutes).&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="delay.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12613iED8ED0DD1C3A3229/image-size/large?v=v2&amp;amp;px=999" role="button" title="delay.PNG" alt="delay.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Could you please help me with this.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rahul&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 05:14:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-indexing-delay/m-p/536615#M7080</guid>
      <dc:creator>rahul2gupta</dc:creator>
      <dc:date>2021-01-21T05:14:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk indexing delay</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-indexing-delay/m-p/536660#M7082</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222802"&gt;@rahul2gupta&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If you are getting logs using Universal Forwarder, delay could be because of the thruput setting on Universal Forwarder. The badwidth limit is default 256KBytes per second, if server creates more the 256 KBytes logs per second, you may experience delays.&lt;/P&gt;&lt;P&gt;This can be confirmed using internal logs of that Universal Forwarder;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal component=ThruputProcessor&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can increase this bandwidth limit on limits.conf on Universal Forwarder; for example to 1024 Kbyte/s&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE&gt;[thruput]
maxKBps = 1024&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this reply helps you an upvote is appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 10:49:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-indexing-delay/m-p/536660#M7082</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-01-21T10:49:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk indexing delay</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-indexing-delay/m-p/536665#M7083</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/206061"&gt;@scelikok&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I checked in the limits.conf and found following configuration.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="thruput.PNG" style="width: 534px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12620i9D0CD4AAA0502284/image-size/large?v=v2&amp;amp;px=999" role="button" title="thruput.PNG" alt="thruput.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 11:08:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-indexing-delay/m-p/536665#M7083</guid>
      <dc:creator>rahul2gupta</dc:creator>
      <dc:date>2021-01-21T11:08:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk indexing delay</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-indexing-delay/m-p/536672#M7084</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222802"&gt;@rahul2gupta&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if you have these problem only on these logs, the problem, is probably the one hinted by&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/206061"&gt;@scelikok&lt;/a&gt;.&lt;/P&gt;&lt;P&gt;At first, check if you have delays in indexing queue (you can see in Splunk Monitor Console).&lt;/P&gt;&lt;P&gt;Then, did you checked the maxKBps parameter on UF or Indexer?&lt;/P&gt;&lt;P&gt;the problem it should be because, by default, an UF has 256 for this parameter.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 12:18:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-indexing-delay/m-p/536672#M7084</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-01-21T12:18:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk indexing delay</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-indexing-delay/m-p/536785#M7085</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I checked these parameters on UF(aeaxxxx) beca&lt;SPAN&gt;use we are facing from this server only.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="thruput.PNG" style="width: 534px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12629i83EE5CF09B16E1CF/image-size/large?v=v2&amp;amp;px=999" role="button" title="thruput.PNG" alt="thruput.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Please let me know if we need to change maxKBps =0 to some higher value.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rahul&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 05:17:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-indexing-delay/m-p/536785#M7085</guid>
      <dc:creator>rahul2gupta</dc:creator>
      <dc:date>2021-01-22T05:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk indexing delay</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-indexing-delay/m-p/536809#M7087</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222802"&gt;@rahul2gupta&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;maxKBps=0 means unlimited, there is no need to change.&lt;/P&gt;&lt;P&gt;Can you check internal logs if you see an error on TailReader component like File Descriptor Cache Full?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal host=aeaxxxx component=TailReader&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If there are too many files monitored, UF cannot monitor all, that may cause delays.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 09:54:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-indexing-delay/m-p/536809#M7087</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-01-22T09:54:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk indexing delay</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-indexing-delay/m-p/536987#M7095</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/206061"&gt;@scelikok&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I Checked the following query and found that latest events generated was on 20/01/2021.&lt;/P&gt;&lt;PRE&gt;index=_internal host=aeaxxxx component=TailReader&lt;/PRE&gt;&lt;P&gt;So what is the solution of this&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face_with_sweat:"&gt;😅&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Still, we see that there is delay in indexing.&lt;span class="lia-unicode-emoji" title=":downcast_face_with_sweat:"&gt;😓&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rahul&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 06:40:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-indexing-delay/m-p/536987#M7095</guid>
      <dc:creator>rahul2gupta</dc:creator>
      <dc:date>2021-01-25T06:40:27Z</dc:date>
    </item>
  </channel>
</rss>

