Getting Data In

Forwarder capacity?

msarro
Builder

I noticed that in the capacity planning guide, there is no mention of the capacity of a forwarder. Right now I am looking at sending a significant amount of data to two different forwarders. How much data can the forwarder handle? These are heavy forwarders, I know the guideline for an indexer is 100GB/day, but I can't find anything similar for forwarders.

Tags (1)
0 Karma

kristian_kolb
Ultra Champion

First: How much is a significant amount?

I think that a lot of this depends on how you set up the forwarding. If you monitor a directory containing thousands of files, with new files being added constantly you may run into problems just because the forwarder will have to keep track of so many files. I've seen forwarders (UF on windows) going up to 35-40% CPU usage for this reason alone (the actual log amount was less than a 100MB daily).

If you have a relatively 'clean' source of logs, i.e. just a few files you could probably send out quite a large amount. The UF is capped at 256KBps, although this can be changed, so in theory this means that a single forwarder can send 21GB/day by default.

hope this helps,

Kristian

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...