Getting Data In

How can I identity forwarder data rate and index data rate (to identify a lag and prioritize logs)?

chintan_shah
Path Finder

Hi,
Is there any way where we can identify how much data the forwarder is sending and how much data is being indexed in real-time?
The problem is that I have a single forwarder that is sending data to a single indexer and its sending multiple logs i.e. 50 monitored files with different indexes. I am receiving data from a few indexes in real time whereas for some indexes I am having a lag, so I want to remove the lag and if possible give higher preferences to some logs file.

0 Karma

yannK
Splunk Employee
Splunk Employee

For forwarder lag, start to look at the metrics.log on the forwarder, if you see that it is hitting a plateau of kbps speed, it may be that you are hitting the default thuput limit.
see this article
http://docs.splunk.com/Documentation/Splunk/7.0.0/Troubleshooting/Troubleshootingeventsindexingdelay...

Also look at the timestamp, maybe is it a timezone issue.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...