Getting Data In

Forwarder capacity?

msarro
Builder

I noticed that in the capacity planning guide, there is no mention of the capacity of a forwarder. Right now I am looking at sending a significant amount of data to two different forwarders. How much data can the forwarder handle? These are heavy forwarders, I know the guideline for an indexer is 100GB/day, but I can't find anything similar for forwarders.

Tags (1)
0 Karma

kristian_kolb
Ultra Champion

First: How much is a significant amount?

I think that a lot of this depends on how you set up the forwarding. If you monitor a directory containing thousands of files, with new files being added constantly you may run into problems just because the forwarder will have to keep track of so many files. I've seen forwarders (UF on windows) going up to 35-40% CPU usage for this reason alone (the actual log amount was less than a 100MB daily).

If you have a relatively 'clean' source of logs, i.e. just a few files you could probably send out quite a large amount. The UF is capped at 256KBps, although this can be changed, so in theory this means that a single forwarder can send 21GB/day by default.

hope this helps,

Kristian

Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...