Getting Data In

After configuring a limit on the forwarder's rate of thruput, why is the maxKBps setting still being exceeded?

Moon629
Explorer

I set up the limits.conf file as the following and save in the path /opt/splunkforwarder/etc/system/local/limits.conf

[thruput]
maxKBps = 512

But when the logs are increasing, sometimes it was exceeded 512Kb, even up to 3000kb.

Can someone please solve this problem? thanks in advance.

0 Karma

sfmandmdev
Path Finder

Which Splunk version are you using?
We reported a bug in 6.3.2 UF recently.

0 Karma

Moon629
Explorer

We didn't upgrade UF, so they are still in 6.2

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Can you confirm you do not have any other apps that are overwriting this setting?

$splunk_home$/splunk btool limits list --debug | grep -i maxkbps

This will show you all configurations that have this applied. I imagine you have an app that is taking priority and overwriting your 512kb setting.

0 Karma

Moon629
Explorer

Below is my search for your reference.

index=_internal source=*metrics*"group=tcpin_connections" "tcp_KBps"  | rename _tcp_KBps as tcp_KBps | table sourceHost, kb, tcp_KBps | where tcp_KBps > 512
0 Karma

Moon629
Explorer

I have run the above command line...but only have one configuration.

./splunk btool limits list --debug | grep -i maxkbps
/opt/splunkforwarder/etc/system/local/limits.conf maxKBps = 512

0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...