Alerting
Highlighted

How to alert which forwarders are throttling?

New Member

How to create an alert for any forwarders that are reaching max thruput consistently?

index=internal source="*splunkd.log" | eval KBps=tcpBps/1024 | stats sum(KBps) as throughput by host | where throughput > 5000 This gives the sum of the thruput for an entire day but I need to know exactly which forwarders are throttling.

0 Karma
Highlighted

Re: How to alert which forwarders are throttling?

SplunkTrust
SplunkTrust

Hi. Can you look at this answer? https://answers.splunk.com/answers/584191/need-a-search-alert-query-when-the-forwarder-reach.html#an...

It's the alert I use to show me the hosts that are being throttled.

View solution in original post

0 Karma
Highlighted

Re: How to alert which forwarders are throttling?

New Member

number of times the hosts are throttling frequently

0 Karma