<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk HF Parallel Pipelines not balanced in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-HF-Parallel-Pipelines-not-balanced/m-p/666621#M9857</link>
    <description>&lt;P&gt;We have configured&amp;nbsp;parallelIngestionPipelines&amp;nbsp;as 2 in Splunk HF as we were facing congestion in the TypingQueue while our CPU was underutilized (~2 Cores used/12).&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;However, the load in the pipelines are not balanced. Pipeline 0 is still congested while Pipeline 1 is barely utilized.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Digging around, this seems to be because 80% of our input is on a single UDP port. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Will splitting the UDP ports on the source itself solve this issue? i.e. having multiple UDP Inputs on the HF instead of one?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 29 Oct 2023 15:39:04 GMT</pubDate>
    <dc:creator>Utkc137</dc:creator>
    <dc:date>2023-10-29T15:39:04Z</dc:date>
    <item>
      <title>Splunk HF Parallel Pipelines not balanced</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-HF-Parallel-Pipelines-not-balanced/m-p/666621#M9857</link>
      <description>&lt;P&gt;We have configured&amp;nbsp;parallelIngestionPipelines&amp;nbsp;as 2 in Splunk HF as we were facing congestion in the TypingQueue while our CPU was underutilized (~2 Cores used/12).&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;However, the load in the pipelines are not balanced. Pipeline 0 is still congested while Pipeline 1 is barely utilized.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Digging around, this seems to be because 80% of our input is on a single UDP port. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Will splitting the UDP ports on the source itself solve this issue? i.e. having multiple UDP Inputs on the HF instead of one?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Oct 2023 15:39:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-HF-Parallel-Pipelines-not-balanced/m-p/666621#M9857</guid>
      <dc:creator>Utkc137</dc:creator>
      <dc:date>2023-10-29T15:39:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk HF Parallel Pipelines not balanced</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-HF-Parallel-Pipelines-not-balanced/m-p/667186#M9872</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;much better option is use some real syslog server or SC4S to collect syslogs. And try to avoid use UDP as it always lost packets!&lt;/P&gt;&lt;PRE&gt;* If the data source is streamed over TCP or UDP, such as syslog sources, 
  only one pipeline will be used.&lt;/PRE&gt;&lt;P&gt;Based on that you cannot increase the UDP performance with adding pipelines.&lt;/P&gt;&lt;P&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 13:55:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-HF-Parallel-Pipelines-not-balanced/m-p/667186#M9872</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-11-02T13:55:52Z</dc:date>
    </item>
  </channel>
</rss>

