Getting Data In

How can I limit forwarding rate from Universal forwarder to Heavy forwarder?

Leon_P
Explorer

Hi All,

We have some remote sites with limited bandwidth that may be offline for periods of time due to their location. I need a way to make sure that when they come back online the Forwarders don't saturate all of the sites bandwidths trying to send all of the data it has built up whilst offline.

I looked at the maxKBps option but this looks like it is just the processed throughput and if the site is offline then it will keep processing and will not limit the output once connected again.

Is my view on maxKBps correct and if so is there an option to limit output?

 

Thanks in Advance

Leon

Labels (3)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @Leon_P,

this is the correct option to limit bandwidth,

In this way, you're sure to not saturate your network when the UF is sending logs.

Ciao.

Giuseppe

View solution in original post

PickleRick
SplunkTrust
SplunkTrust

As @gcusello already said - this is the way to limit your output because your output starts with the throughput.

But there are some caveats worth being aware of.

1. The maxKBps is per pipeline. So if you have multiple pipelines, your max cumulative throughput will be maxKBps multiplied by number of pipelines.

2. The throughput limit "pushes down" on inputs by filling queues. Depending on the input type (and its settings) it may lead to loss of events if you hit the limit. For example for "push type" inputs (like syslog receiver ports), you might start losing events if your queues get full and inputs have no space to write to.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Leon_P,

this is the correct option to limit bandwidth,

In this way, you're sure to not saturate your network when the UF is sending logs.

Ciao.

Giuseppe

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...