Getting Data In

How can I limit forwarding rate from Universal forwarder to Heavy forwarder?

Leon_P
Explorer

Hi All,

We have some remote sites with limited bandwidth that may be offline for periods of time due to their location. I need a way to make sure that when they come back online the Forwarders don't saturate all of the sites bandwidths trying to send all of the data it has built up whilst offline.

I looked at the maxKBps option but this looks like it is just the processed throughput and if the site is offline then it will keep processing and will not limit the output once connected again.

Is my view on maxKBps correct and if so is there an option to limit output?

 

Thanks in Advance

Leon

Labels (3)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @Leon_P,

this is the correct option to limit bandwidth,

In this way, you're sure to not saturate your network when the UF is sending logs.

Ciao.

Giuseppe

View solution in original post

PickleRick
SplunkTrust
SplunkTrust

As @gcusello already said - this is the way to limit your output because your output starts with the throughput.

But there are some caveats worth being aware of.

1. The maxKBps is per pipeline. So if you have multiple pipelines, your max cumulative throughput will be maxKBps multiplied by number of pipelines.

2. The throughput limit "pushes down" on inputs by filling queues. Depending on the input type (and its settings) it may lead to loss of events if you hit the limit. For example for "push type" inputs (like syslog receiver ports), you might start losing events if your queues get full and inputs have no space to write to.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Leon_P,

this is the correct option to limit bandwidth,

In this way, you're sure to not saturate your network when the UF is sending logs.

Ciao.

Giuseppe

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...