Getting Data In

Domain controller data ingestion delay

rahulg
Explorer

Hi, facing issue with  data ingestion for the windows security events from the domain controller servers

index=wineventlog source=WinEventLog:Security

any suggestion, solution here?

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Set maxKBps=0 on the forwarders on each DC.

---
If this reply helps you, Karma would be appreciated.
0 Karma

rahulg
Explorer

so far I have tried, below windows addon changes as per the splunk

[WinEventLog://Security]
evt_resolve_ad_obj = 0

and change  limits.conf
# selt maxkbps to 4096
[thruput]
maxKBps = 4096

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...