Getting Data In

Do we have any SPLUNK recommended maximum size of a single source file for UFs to push?

SplunkDash
Motivator

Hello,

Do we have any SPLUNK recommended maximum size of a single source file for UFs to push? I know maximus size of Lookup is 500MB. But for SPLUNK UF based data ingestion, I have a few source files need to be ingested every day using UF and each of the size of source files is around 2.2 GB. Do you have any recommendations? Thank you so much.

Labels (1)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Hi

I haven’t seen any recommendations for ingested files. More important is how much events come to it and could UF read it faster than new events come! This situation could cause delays for source events on this host especially if there are lot of files. 2.2GB/day isn’t any issue for UF if your source node can handle to generate that log.

r. Ismo

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

Hi

I haven’t seen any recommendations for ingested files. More important is how much events come to it and could UF read it faster than new events come! This situation could cause delays for source events on this host especially if there are lot of files. 2.2GB/day isn’t any issue for UF if your source node can handle to generate that log.

r. Ismo

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Building Momentum: Splunk Developer Program at .conf25

At Splunk, developers are at the heart of innovation. That’s why this year at .conf25, we officially launched ...