Dashboards & Visualizations

How does Splunk forward events?

nicholashouston
Engager

How does Splunk handle events when forwarded? Does it send them one event at a time or in batches?

I.E.: I am using a heavy forwarder to send a copy of my data off site through a router that collects NetFlow information. My concern is will the recursively created NetFlow records increase uncontrollably if it is monitoring its own output?

Netflow is set to capture session data and then forward it to Splunk.

0 Karma
1 Solution

coccyx
Path Finder

Splunk by default will stick on a given indexer for 30 seconds from a heavy forwarder before connecting to another. This can lead to inconsistent load balancing but there are things you can do to tune it better.

Your concern about Netflow into Splunk also creating a lot of connections via Splunk isn't a valid concern. Splunk sends megabytes or gigabytes of data per TCP connection before establishing another connection. There may be thousands or millions of Netflow records in that stream. Splunk should not meaningfully add to your Netflow record count from HWF to Indexer. On the front side of the HWF, depending on the number of Universal Forwarders though, you could see a significant number of connections. Enough to be a meaningful percentage of your Netflow data.

View solution in original post

coccyx
Path Finder

Splunk by default will stick on a given indexer for 30 seconds from a heavy forwarder before connecting to another. This can lead to inconsistent load balancing but there are things you can do to tune it better.

Your concern about Netflow into Splunk also creating a lot of connections via Splunk isn't a valid concern. Splunk sends megabytes or gigabytes of data per TCP connection before establishing another connection. There may be thousands or millions of Netflow records in that stream. Splunk should not meaningfully add to your Netflow record count from HWF to Indexer. On the front side of the HWF, depending on the number of Universal Forwarders though, you could see a significant number of connections. Enough to be a meaningful percentage of your Netflow data.

richgalloway
SplunkTrust
SplunkTrust

Heavy forwarders forward data in batches. I forget the size of the batch ATM.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...