Getting Data In

Data transfer rate between forward and indexer.

clyde772
Communicator

Has anybody experienced condition where Forwarder is not reading and sending old logs fast? Eventhough there's plenty of bandwidth between forwarder and Indexer?

I have a feeling that Splunk forwarder is intentionally forwarding data at a low rate to reduce load on the network and the server when the data that's being indexed is old (not current) data.

Does splunk intelligently rate data transfers and index speed based on age of the data?

Tags (1)
0 Karma

Ayn
Legend

Is this a Universal Forwarder? UF's have a default data transfer rate capped at 256Kbps.

http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Introducingtheuniversalforwarder

0 Karma

sdaniels
Splunk Employee
Splunk Employee

Maybe someone overrode the default setting in limits.conf?

http://splunk-base.splunk.com/answers/1810/store-and-forward-and-bandwidth-contraints

[thruput]

maxKBps =
* If specified and not zero, this limits the speed through the thruput processor to the specified
rate in kilobytes per second.
* To control the CPU load while indexing, use this to throttle the number of events this indexer
processes to the rate (in KBps) you specify.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...