Getting Data In

How to limit heavy forwarder bandwidth in limits.conf?

splunkreal
Influencer

Hello guys,

is it possible to limit Heavy forwarders bandwidth like UF (setting [thruput] in limits.conf for forwarders)?

Thanks.

* If this helps, please upvote or accept solution if it solved *
Labels (2)
0 Karma
1 Solution

splunkreal
Influencer

From support : "Splunk Heavy Forwarder does not have setting to limit network bandwidth."

* If this helps, please upvote or accept solution if it solved *

View solution in original post

0 Karma

splunkreal
Influencer

From support : "Splunk Heavy Forwarder does not have setting to limit network bandwidth."

* If this helps, please upvote or accept solution if it solved *
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @realsplunk,
yes it's the same thing, only one hint beware to the traffic to avoid that your HF will be the bottle neck of your network.

Ciao.
Giuseppe

0 Karma

splunkreal
Influencer

Hi Cusello,
we have +800 KB/s indexing Checkpoint through OPSEC app and other syslogs through tcp/udp basically.

Here are the confs :

[root@HFSIEM01 ~]# grep -r -i maxKBps /OPT/siem/splunk/etc
/OPT/siem/splunk/etc/system/README/server.conf.spec:    1. maxKBps (in limits.conf)
/OPT/siem/splunk/etc/system/README/limits.conf.spec:maxKBps = <integer>
/OPT/siem/splunk/etc/system/README/limits.conf.spec:  * The thruput processor applies the 'maxKBps' setting for each
/OPT/siem/splunk/etc/system/README/limits.conf.spec:    pipelines, the processor multiplies the 'maxKBps' value

/OPT/siem/splunk/etc/system/default/limits.conf:maxKBps = 0
/OPT/siem/splunk/etc/apps/SplunkLightForwarder/default/limits.conf:maxKBps = 256

If I understand conf file precedence and if it applied, the limit should be 256?

Thanks.

* If this helps, please upvote or accept solution if it solved *
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automated Threat Analysis: Available in ES Premier

Automated Threat Analysis: Centralize and Accelerate Phishing Investigations in Splunk Enterprise ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...