Deployment Architecture

Does increase in TCPOutput Queue cause forwarder to use more memory

vr2312
Builder

We came across an issue this past weekend where the UF on a Windows Server was utilizing high memory usage and when we dug deep, we identified the cause to be Splunk.

While expanding our investigation we can observe the host impacted have a good amount of data waiting.

is this possible that the memory usage was high because of this ?

0 Karma
1 Solution

masonmorales
Influencer

Yes. Splunk queues in memory by default. You can lower the queue size and use persistent queueing to write to disk instead, which will conserve memory.

View solution in original post

masonmorales
Influencer

Yes. Splunk queues in memory by default. You can lower the queue size and use persistent queueing to write to disk instead, which will conserve memory.

Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...