Getting Data In

Can you help us with a data input problem?

makhambayeva
New Member

Splunk Enterprise is installed on server and received some data according to some port, but after some time some troubles occur. You can see this in attachments. How can we solve this?

alt text

0 Karma

solarboyz1
Builder

It appear the Splunk instance you are sending your data to is getting overloaded, it cannot keep up with the amount of incoming data.

My guess is you need more resources to keep up with the incoming data.

If this is intermittent when spikes of data occur, you may be able to increase your network queue sizes to hold more data. This may allow the queue to hold the data during a spike, provided the incoming data eventually decrease so the queues can be emptied.

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...