Getting Data In

Does a universal forwarder's persistent queue exist after a reboot?

dflodstrom
Builder

According to this document: http://docs.splunk.com/Documentation/Splunk/6.4.0/Data/Usepersistentqueues

The in-memory data can get lost if a crash occurs. Similarly, data that is in the parsing or indexing pipeline but that has not yet been written to disk can get lost in the event of a crash.

This only refers to a 'crash'. Does Splunk write the 500K of cached data to the persistent queue in the event of a clean shutdown of the forwarder or the machine?

0 Karma
1 Solution

jonathan_cooper
Communicator

Yes, part of the shutdown of the service is to wait for all queues to finish. This is why Splunkd can take longer to restart at times, you can watch this happening in the logs.

View solution in original post

jonathan_cooper
Communicator

Yes, part of the shutdown of the service is to wait for all queues to finish. This is why Splunkd can take longer to restart at times, you can watch this happening in the logs.

dflodstrom
Builder

Excellent. Thanks, Cooper! We're thinking about installing UFs on laptops and this was one of our concerns.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mile High Learning with Splunk University, Denver, Colorado

If Denver is known for its mile-high elevation, Splunk University is about to raise the bar on technical ...

IT Service Intelligence 5.0 Series: Your Guide to the June Launch

We are excited to announce the June release of Splunk IT Service Intelligence (ITSI) 5.0. This update ...

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...