Deployment Architecture

Does the blocking of a heavy forwarder cause data drop or event drop?

vrmandadi
Builder

I got a message that the TCP output processor has paused data flow. Forwarding to output group heavy forwarder has blocked for 3570 seconds. This will probably stall the data flow towards indexing and other network outputs.

1)Does this cause data drop
2)Does it catch up the data once it is free
3)How to set up the persistent queue and where for addressing these issues
4)How to create an alert for these type of issues or when the queue is full

Thanks in advance.

0 Karma

adonio
Ultra Champion

hello there,
1) if persistent queue is full, then data will start dropping - default size for queue is 500kb
2) supposed to, depends on the type of input
3) see link below
4) there are many methods, one will be to look for the string in _internal index for example and alert on it.

all your answers are in this link:
https://docs.splunk.com/Documentation/Splunk/latest/Data/Usepersistentqueues

hope it helps

Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...