<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: configuring receiver in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/configuring-receiver/m-p/71792#M180896</link>
    <description>&lt;P&gt;There are people who are using hundreds more forwarders than the number you've specified without any issues. As a general rule, I wouldn't say that 30 is too many unless you're having some type of performance problem. In short, I think you're probably just fine with that configuration. &lt;/P&gt;</description>
    <pubDate>Mon, 11 Jun 2012 14:33:45 GMT</pubDate>
    <dc:creator>jbsplunk</dc:creator>
    <dc:date>2012-06-11T14:33:45Z</dc:date>
    <item>
      <title>configuring receiver</title>
      <link>https://community.splunk.com/t5/Splunk-Search/configuring-receiver/m-p/71789#M180893</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;In our environment ,there are almost 30 servers where splunk forwarders are installed for monitoring and there is only one splunk indexer.I've configured only one receiver for the all 30 forwader servers.Is this the recommended way? or should I split it as a group and configure more receivers?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2012 11:33:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/configuring-receiver/m-p/71789#M180893</guid>
      <dc:creator>splunker_123</dc:creator>
      <dc:date>2012-06-11T11:33:57Z</dc:date>
    </item>
    <item>
      <title>Re: configuring receiver</title>
      <link>https://community.splunk.com/t5/Splunk-Search/configuring-receiver/m-p/71790#M180894</link>
      <description>&lt;P&gt;Are you experiencing performance issues then?&lt;/P&gt;

&lt;P&gt;You should look at the following &lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/installation/capacityplanningforalargersplunkdeployment"&gt;http://docs.splunk.com/Documentation/Splunk/latest/installation/capacityplanningforalargersplunkdeployment&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2012 11:55:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/configuring-receiver/m-p/71790#M180894</guid>
      <dc:creator>MHibbin</dc:creator>
      <dc:date>2012-06-11T11:55:03Z</dc:date>
    </item>
    <item>
      <title>Re: configuring receiver</title>
      <link>https://community.splunk.com/t5/Splunk-Search/configuring-receiver/m-p/71791#M180895</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;No,we haven't tested yet..just we are in starting phase.but just wondering is this way of configuration recommended?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2012 13:54:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/configuring-receiver/m-p/71791#M180895</guid>
      <dc:creator>splunker_123</dc:creator>
      <dc:date>2012-06-11T13:54:11Z</dc:date>
    </item>
    <item>
      <title>Re: configuring receiver</title>
      <link>https://community.splunk.com/t5/Splunk-Search/configuring-receiver/m-p/71792#M180896</link>
      <description>&lt;P&gt;There are people who are using hundreds more forwarders than the number you've specified without any issues. As a general rule, I wouldn't say that 30 is too many unless you're having some type of performance problem. In short, I think you're probably just fine with that configuration. &lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2012 14:33:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/configuring-receiver/m-p/71792#M180896</guid>
      <dc:creator>jbsplunk</dc:creator>
      <dc:date>2012-06-11T14:33:45Z</dc:date>
    </item>
    <item>
      <title>Re: configuring receiver</title>
      <link>https://community.splunk.com/t5/Splunk-Search/configuring-receiver/m-p/71793#M180897</link>
      <description>&lt;P&gt;Did I say 30 ,my bad, it's 70 forwaders actually.I'm sorry&lt;BR /&gt;
Do you still think this is going to be fine configuration.?&lt;BR /&gt;
I know you said it depends on performance but the point I'm trying to ask  is..is there anyone facing some issues with these numbers,if so I dont want to run into issues later?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2012 16:18:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/configuring-receiver/m-p/71793#M180897</guid>
      <dc:creator>splunker_123</dc:creator>
      <dc:date>2012-06-11T16:18:48Z</dc:date>
    </item>
    <item>
      <title>Re: configuring receiver</title>
      <link>https://community.splunk.com/t5/Splunk-Search/configuring-receiver/m-p/71794#M180898</link>
      <description>&lt;P&gt;70 should be fine as well. Some people have hundreds of forwarders sending data. The question is one of bottlenecks created by the receiving system. Keep in mind that splunk uses a lot of file handlers, and that you need to be able to sustain 800-1000 iops.   If the indexer is beefy, and configured properly, you'll be fine.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2012 16:21:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/configuring-receiver/m-p/71794#M180898</guid>
      <dc:creator>jbsplunk</dc:creator>
      <dc:date>2012-06-11T16:21:56Z</dc:date>
    </item>
    <item>
      <title>Re: configuring receiver</title>
      <link>https://community.splunk.com/t5/Splunk-Search/configuring-receiver/m-p/71795#M180899</link>
      <description>&lt;P&gt;ah awesome..thankyou so much&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2012 21:41:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/configuring-receiver/m-p/71795#M180899</guid>
      <dc:creator>splunker_123</dc:creator>
      <dc:date>2012-06-11T21:41:51Z</dc:date>
    </item>
  </channel>
</rss>

