Getting Data In

How to limit heavy forwarder bandwidth in limits.conf?

splunkreal
Motivator

Hello guys,

is it possible to limit Heavy forwarders bandwidth like UF (setting [thruput] in limits.conf for forwarders)?

Thanks.

* If this helps, please upvote or accept solution if it solved *
Labels (2)
0 Karma
1 Solution

splunkreal
Motivator

From support : "Splunk Heavy Forwarder does not have setting to limit network bandwidth."

* If this helps, please upvote or accept solution if it solved *

View solution in original post

0 Karma

splunkreal
Motivator

From support : "Splunk Heavy Forwarder does not have setting to limit network bandwidth."

* If this helps, please upvote or accept solution if it solved *
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @realsplunk,
yes it's the same thing, only one hint beware to the traffic to avoid that your HF will be the bottle neck of your network.

Ciao.
Giuseppe

0 Karma

splunkreal
Motivator

Hi Cusello,
we have +800 KB/s indexing Checkpoint through OPSEC app and other syslogs through tcp/udp basically.

Here are the confs :

[root@HFSIEM01 ~]# grep -r -i maxKBps /OPT/siem/splunk/etc
/OPT/siem/splunk/etc/system/README/server.conf.spec:    1. maxKBps (in limits.conf)
/OPT/siem/splunk/etc/system/README/limits.conf.spec:maxKBps = <integer>
/OPT/siem/splunk/etc/system/README/limits.conf.spec:  * The thruput processor applies the 'maxKBps' setting for each
/OPT/siem/splunk/etc/system/README/limits.conf.spec:    pipelines, the processor multiplies the 'maxKBps' value

/OPT/siem/splunk/etc/system/default/limits.conf:maxKBps = 0
/OPT/siem/splunk/etc/apps/SplunkLightForwarder/default/limits.conf:maxKBps = 256

If I understand conf file precedence and if it applied, the limit should be 256?

Thanks.

* If this helps, please upvote or accept solution if it solved *
0 Karma
Get Updates on the Splunk Community!

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...

Explore the Latest Educational Offerings from Splunk [January 2025 Updates]

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...