All Apps and Add-ons

How to find the delay/latency factor induced by Splunk?

bkumarm
Contributor

We have a setup where the logs are generated continuously and are being forwarded into Splunk indexers and also into another external application.
Earlier, the application was directly reading from the server with minimal delay.
After we introduced Splunk, we are observing delay of about 13 to 19 secs.
The maximum approved delay factor is 5 secs.
How do I find out where is the delay being induced?
I have _time which is the event occurrence time, _indextime which gives indexed time. Using Splunk App for Stream, I am able to get timestamp factor too.
However, I am struggling to get the logic of where the delay is.
Basically, if I can get the time of arrival of log into Splunk, I can calculate the difference between index time and arrival time.

How do I get the arrival time into Splunk?
Any ideas? Any one faced such situation?

0 Karma
1 Solution

vshcherbakov_sp
Splunk Employee
Splunk Employee

Hello,

You can get the time of arrival into splunk (i.e. the event's index time) via the _indextime field.

View solution in original post

0 Karma

vshcherbakov_sp
Splunk Employee
Splunk Employee

Hello,

You can get the time of arrival into splunk (i.e. the event's index time) via the _indextime field.

0 Karma
Get Updates on the Splunk Community!

Accelerate Service Onboarding, Decomposition, Troubleshooting - and more with ITSI’s ...

Accelerate Service Onboarding, Decomposition, Troubleshooting - and more! Faster Time to ValueManaging and ...

New Release | Splunk Enterprise 9.3

Admins and Analyst can benefit from:  Seamlessly route data to your local file system to save on storage ...

2024 Splunk Career Impact Survey | Earn a $20 gift card for participating!

Hear ye, hear ye! The time has come again for Splunk's annual Career Impact Survey!  We need your help by ...