<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: EPS in flat file with universal forwarder in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/EPS-in-flat-file-with-universal-forwarder/m-p/683845#M233466</link>
    <description>&lt;P&gt;It depends on the size of an event.&amp;nbsp; The UF is rate-limited by the &lt;FONT face="courier new,courier"&gt;maxKBps&lt;/FONT&gt; setting in limits.conf.&lt;/P&gt;</description>
    <pubDate>Wed, 10 Apr 2024 18:16:57 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2024-04-10T18:16:57Z</dc:date>
    <item>
      <title>EPS in flat file with universal forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Search/EPS-in-flat-file-with-universal-forwarder/m-p/683840#M233465</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;what is the &lt;SPAN&gt;Events-per-second (&lt;/SPAN&gt;EPS) in flat file with universal forwarder?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 17:30:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/EPS-in-flat-file-with-universal-forwarder/m-p/683840#M233465</guid>
      <dc:creator>Meet-Patel</dc:creator>
      <dc:date>2024-04-10T17:30:15Z</dc:date>
    </item>
    <item>
      <title>Re: EPS in flat file with universal forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Search/EPS-in-flat-file-with-universal-forwarder/m-p/683845#M233466</link>
      <description>&lt;P&gt;It depends on the size of an event.&amp;nbsp; The UF is rate-limited by the &lt;FONT face="courier new,courier"&gt;maxKBps&lt;/FONT&gt; setting in limits.conf.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 18:16:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/EPS-in-flat-file-with-universal-forwarder/m-p/683845#M233466</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-04-10T18:16:57Z</dc:date>
    </item>
    <item>
      <title>Re: EPS in flat file with universal forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Search/EPS-in-flat-file-with-universal-forwarder/m-p/683848#M233467</link>
      <description>&lt;P&gt;It's a bit more complicated than that.&lt;/P&gt;&lt;P&gt;1. As &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt; pointed out, UF is by default capped with maxKBps (which is a rough value - there is no guarantee for Splunk to _always_ process no more than that value per second).&lt;/P&gt;&lt;P&gt;2. Even if you set the limit to 0 (no limit at all), the back pressure from output will make the forwarder to stop reading the file until the queue empties a bit.&lt;/P&gt;&lt;P&gt;Generally, the "speed" of Splunk reading files depends mostly on non-Splunk limits (like output rate which might be limited by receiving instance performance or network bandwidth or input rate if the file is placed on a network share). Also since the limits apply to the general overall size of the data regardless of how big the events are, the EPS value isn't that important here - the same limit will apply if you send just a few big events as when you send many small ones.&lt;/P&gt;&lt;P&gt;But there is also one more thing worth pointing out - UF doesn't (typically, unless you use indexed extractions on structured data) deal with events as such - it reads and sends to an output chunks of data for breaking into events "further down the road" (on indexers or heavy forwarders). With sufficiently modern UF and configured EVENT_BREAKER, you should be sending chunks of data ending on event boundary, but you typically don't send single events (unless they are huge).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 18:58:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/EPS-in-flat-file-with-universal-forwarder/m-p/683848#M233467</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-04-10T18:58:15Z</dc:date>
    </item>
    <item>
      <title>Re: EPS in flat file with universal forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Search/EPS-in-flat-file-with-universal-forwarder/m-p/683881#M233486</link>
      <description>&lt;P&gt;I would appreciate it if there were any documents on Events-per-second (EPS) recorded in a flat file with universal forwarder.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2024 06:36:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/EPS-in-flat-file-with-universal-forwarder/m-p/683881#M233486</guid>
      <dc:creator>Meet-Patel</dc:creator>
      <dc:date>2024-04-11T06:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: EPS in flat file with universal forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Search/EPS-in-flat-file-with-universal-forwarder/m-p/683886#M233488</link>
      <description>&lt;P&gt;What is your business problem?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2024 08:16:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/EPS-in-flat-file-with-universal-forwarder/m-p/683886#M233488</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-04-11T08:16:14Z</dc:date>
    </item>
    <item>
      <title>Re: EPS in flat file with universal forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Search/EPS-in-flat-file-with-universal-forwarder/m-p/683892#M233489</link>
      <description>&lt;P&gt;We want to read log files (approx. 100 of GBs) and send them through Splunk forwarder before setting up, We need to verify the Events-per-second (EPS) recorded in a flat file with Universal Forwarder.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2024 11:03:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/EPS-in-flat-file-with-universal-forwarder/m-p/683892#M233489</guid>
      <dc:creator>Meet-Patel</dc:creator>
      <dc:date>2024-04-11T11:03:42Z</dc:date>
    </item>
    <item>
      <title>Re: EPS in flat file with universal forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Search/EPS-in-flat-file-with-universal-forwarder/m-p/683895#M233491</link>
      <description>&lt;P&gt;OK. Have you read anything that has been written in this thread? EPS as such is not a very important concept for Splunk (at least not on the UF level).&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2024 12:28:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/EPS-in-flat-file-with-universal-forwarder/m-p/683895#M233491</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-04-11T12:28:42Z</dc:date>
    </item>
    <item>
      <title>Re: EPS in flat file with universal forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Search/EPS-in-flat-file-with-universal-forwarder/m-p/683896#M233492</link>
      <description>&lt;P&gt;I find it interesting that you give the log file size in GB rather than events yet you expect UF documentation to provide EPS.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;has explained why we cannot offer an EPS number and also why any talk about data rates is a guess at best.&lt;/P&gt;&lt;P&gt;A Splunk UF is very capable of handling 100GBs of log files.&amp;nbsp; Many customers do so regularly.&lt;/P&gt;&lt;P&gt;Why problem are you trying to solve?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2024 12:29:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/EPS-in-flat-file-with-universal-forwarder/m-p/683896#M233492</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-04-11T12:29:50Z</dc:date>
    </item>
    <item>
      <title>Re: EPS in flat file with universal forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Search/EPS-in-flat-file-with-universal-forwarder/m-p/683901#M233495</link>
      <description>&lt;P&gt;Anyway, obsessing about EPS suggests that you might be thinking about replacing some other SIEM/log management solution. Those used to be licensed on a per-EPS basis. With Splunk it doesn't matter. If ingest-based your license allows for indexing specified volume of data _daily_ regardless of whether it's a constant steady data stream or if it's just a few "batches" of high volume peaks of data.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2024 13:18:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/EPS-in-flat-file-with-universal-forwarder/m-p/683901#M233495</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-04-11T13:18:59Z</dc:date>
    </item>
    <item>
      <title>Re: EPS in flat file with universal forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Search/EPS-in-flat-file-with-universal-forwarder/m-p/684019#M233517</link>
      <description>&lt;P&gt;I am looking for something similar to this.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/WindowsAddOn/8.1.2/User/PerformancereferencefortheSplunkAdd-onforWindows" target="_blank"&gt;https://docs.splunk.com/Documentation/WindowsAddOn/8.1.2/User/PerformancereferencefortheSplunkAdd-onforWindows&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2024 12:14:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/EPS-in-flat-file-with-universal-forwarder/m-p/684019#M233517</guid>
      <dc:creator>Meet-Patel</dc:creator>
      <dc:date>2024-04-12T12:14:45Z</dc:date>
    </item>
    <item>
      <title>Re: EPS in flat file with universal forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Search/EPS-in-flat-file-with-universal-forwarder/m-p/684025#M233518</link>
      <description>&lt;P&gt;That document is for a specific source where the event size is well-defined.&amp;nbsp; The information there cannot be generalized because the size of an "event" is unknown.&amp;nbsp; I've seen event sizes range from &amp;lt;100 to &amp;gt;100,000 bytes so it is very difficult to produce an EPS number without knowing more about the data you wish to ingest.&lt;/P&gt;&lt;P&gt;It's possible the documentation for other TAs provides the information you seek.&amp;nbsp; Have you looked at the TAs for your data?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2024 14:05:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/EPS-in-flat-file-with-universal-forwarder/m-p/684025#M233518</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-04-12T14:05:54Z</dc:date>
    </item>
    <item>
      <title>Re: EPS in flat file with universal forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Search/EPS-in-flat-file-with-universal-forwarder/m-p/684027#M233519</link>
      <description>&lt;P&gt;Apart from all that &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt; already mentioned, this document shows results of testing on some particular reference hardware. It's by no means a guarantee that an input will work with this performance.&lt;/P&gt;&lt;P&gt;Also remember that windows eventlog inputs get the logs by calling the system using winapi whereas file input just reads the file straight from the disk (most probably using memory-mapped files since it's most effective method).&lt;/P&gt;&lt;P&gt;And last but definitely not least - as I already pointed out - UF typically doesn't break data into events!&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2024 14:21:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/EPS-in-flat-file-with-universal-forwarder/m-p/684027#M233519</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-04-12T14:21:12Z</dc:date>
    </item>
  </channel>
</rss>

