<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk UF performance issue, not forward all logs data in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-UF-performance-issue-not-forward-all-logs-data/m-p/491654#M4073</link>
    <description>&lt;P&gt;What do the &lt;CODE&gt;inputs.conf&lt;/CODE&gt; entries look like?&lt;/P&gt;

&lt;P&gt;What is the system load on your log aggregator?&lt;/P&gt;

&lt;P&gt;How big is your Splunk env?&lt;/P&gt;

&lt;P&gt;What network components (firewalls, load balancers, etc) are between the collector and Splunk?&lt;/P&gt;</description>
    <pubDate>Fri, 13 Mar 2020 13:10:34 GMT</pubDate>
    <dc:creator>wmyersas</dc:creator>
    <dc:date>2020-03-13T13:10:34Z</dc:date>
    <item>
      <title>Splunk UF performance issue, not forward all logs data</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-UF-performance-issue-not-forward-all-logs-data/m-p/491653#M4072</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;

&lt;P&gt;In my NFS server, Splunk UF is installed. That NFS server is basically a log storage server, &lt;BR /&gt;
log rotation daemon also running on that server that convert file to gzip file after 24 hours, in same location.&lt;BR /&gt;
NFS server is a single server, and it have really big amount of data.&lt;/P&gt;

&lt;P&gt;But some time my UF don't forward some files data from NFS server to my Indexers server. &lt;BR /&gt;
Many files remain missing in my Splunk indexers.&lt;/P&gt;

&lt;P&gt;Following parameters are same for many of the sourcetype in props.conf ( Yes, many events are really big)&lt;BR /&gt;
TRUNCATE = 20000&lt;BR /&gt;
MAX_EVENTS = 512&lt;BR /&gt;
BREAK_ONLY_BEFORE = &amp;lt; [Set] &amp;gt; &lt;/P&gt;

&lt;P&gt;Please suggest how I improve my UF performance.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:33:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-UF-performance-issue-not-forward-all-logs-data/m-p/491653#M4072</guid>
      <dc:creator>arun_kant_sharm</dc:creator>
      <dc:date>2020-09-30T04:33:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UF performance issue, not forward all logs data</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-UF-performance-issue-not-forward-all-logs-data/m-p/491654#M4073</link>
      <description>&lt;P&gt;What do the &lt;CODE&gt;inputs.conf&lt;/CODE&gt; entries look like?&lt;/P&gt;

&lt;P&gt;What is the system load on your log aggregator?&lt;/P&gt;

&lt;P&gt;How big is your Splunk env?&lt;/P&gt;

&lt;P&gt;What network components (firewalls, load balancers, etc) are between the collector and Splunk?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2020 13:10:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-UF-performance-issue-not-forward-all-logs-data/m-p/491654#M4073</guid>
      <dc:creator>wmyersas</dc:creator>
      <dc:date>2020-03-13T13:10:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UF performance issue, not forward all logs data</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-UF-performance-issue-not-forward-all-logs-data/m-p/491655#M4074</link>
      <description>&lt;P&gt;In my splunk env I have one NFS server (for log collection), in that server UF is installed. That contain input.conf file, props.conf . file. In input.conf file, we have to monitor some directory that forward data to particular Index, using sourcetype define in props.conf.&lt;/P&gt;

&lt;P&gt;That NFS server is on premise server, its forward data on 6 indexer, indexer are EC2 instances, that share same   AWS- route53 , in round-robin technique (So no ALB/NLB/ELB in between indexers). Yes I can manage that NFS server also using one Splunk-Master server. Indexer cold and frozen bucket are AWS-EFS drives, that are same between all indexers. Apart of this some Search Head servers, yes SH connected to ALB and then route 53.&lt;/P&gt;

&lt;P&gt;In indexer server I continuously store data of other on premise servers, AWS-Servers, Openshift Server, DB Servers, SysLogs servers.    &lt;/P&gt;</description>
      <pubDate>Sat, 14 Mar 2020 06:55:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-UF-performance-issue-not-forward-all-logs-data/m-p/491655#M4074</guid>
      <dc:creator>arun_kant_sharm</dc:creator>
      <dc:date>2020-03-14T06:55:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UF performance issue, not forward all logs data</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-UF-performance-issue-not-forward-all-logs-data/m-p/491656#M4075</link>
      <description>&lt;P&gt;You have to have good hygiene for old logs.  Hundreds of co-resident logs is fine, thousands is risky, above that you will experience a total breakdown in the UF's ability to search through them and send updates in a timely manner.   Even if the &lt;CODE&gt;*.tgz&lt;/CODE&gt; does not match your &lt;CODE&gt;monitor&lt;/CODE&gt; pattern, they will still cause this problem unless you MOVE THEM SOMEWHERE ELSE.&lt;/P&gt;</description>
      <pubDate>Sat, 14 Mar 2020 17:38:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-UF-performance-issue-not-forward-all-logs-data/m-p/491656#M4075</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2020-03-14T17:38:00Z</dc:date>
    </item>
  </channel>
</rss>

