Getting Data In

Do we have any SPLUNK recommended maximum size of a single source file for UFs to push?

SplunkDash
Motivator

Hello,

Do we have any SPLUNK recommended maximum size of a single source file for UFs to push? I know maximus size of Lookup is 500MB. But for SPLUNK UF based data ingestion, I have a few source files need to be ingested every day using UF and each of the size of source files is around 2.2 GB. Do you have any recommendations? Thank you so much.

Labels (1)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Hi

I haven’t seen any recommendations for ingested files. More important is how much events come to it and could UF read it faster than new events come! This situation could cause delays for source events on this host especially if there are lot of files. 2.2GB/day isn’t any issue for UF if your source node can handle to generate that log.

r. Ismo

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

Hi

I haven’t seen any recommendations for ingested files. More important is how much events come to it and could UF read it faster than new events come! This situation could cause delays for source events on this host especially if there are lot of files. 2.2GB/day isn’t any issue for UF if your source node can handle to generate that log.

r. Ismo

Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...