Getting Data In

Do we have any SPLUNK recommended maximum size of a single source file for UFs to push?

SplunkDash
Motivator

Hello,

Do we have any SPLUNK recommended maximum size of a single source file for UFs to push? I know maximus size of Lookup is 500MB. But for SPLUNK UF based data ingestion, I have a few source files need to be ingested every day using UF and each of the size of source files is around 2.2 GB. Do you have any recommendations? Thank you so much.

Labels (1)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Hi

I haven’t seen any recommendations for ingested files. More important is how much events come to it and could UF read it faster than new events come! This situation could cause delays for source events on this host especially if there are lot of files. 2.2GB/day isn’t any issue for UF if your source node can handle to generate that log.

r. Ismo

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

Hi

I haven’t seen any recommendations for ingested files. More important is how much events come to it and could UF read it faster than new events come! This situation could cause delays for source events on this host especially if there are lot of files. 2.2GB/day isn’t any issue for UF if your source node can handle to generate that log.

r. Ismo

Get Updates on the Splunk Community!

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...