Getting Data In

Are there practical limits to queue sizing on indexers?

twinspop
Influencer

We had an issue with parsing queue filling recently. Our oversized event profile is to blame. To address, I increased our queue size across the board to 100 MB from 50 MB. Is there any reason not to go higher? 1 GB? Given an indexer with unlimited RAM, is there a point of diminishing returns when it comes to queue sizing? Do the different queues have different PoDRs?

terminaloutcome
Path Finder

We've run pretty high queue sizes in the order of multiple gigabytes - but if you've got regular massive queues instead of short-term spikes you're probably focusing on the wrong problem. Ensure that you've sized your servers appropriately for the load, and tune the processing path to make sure you're not unnecessarily holding up data.

Get Updates on the Splunk Community!

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...