I create a forwarder on a remote site. The speed of network is limited. I need transfer the event log in middle-night on the forwarder.
How can I configure the transfer start at middle-night, pause at six o'clock?
Thank you in advance.
Create a batch script that reduce the thruput during day time, and unleash the beast at night.
I assume that you are on windows
# default was 256
# for unlimited
Then at night time run a batch using the windows scheduler (running under the correct user of course)
cp %SPLUNK_HOME%\etc\system\local\limits.conf_superfast %SPLUNK_HOME%\etc\system\local\limits.conf
and in the morning
cp %SPLUNK_HOME%\etc\system\local\limits.conf_superslow %SPLUNK_HOME%\etc\system\local\limits.conf
@shizl, There are couple of ways to accomplish what your want or least come close, scripted input or oneshot. Please read my previous post. Hope this helps.
If your network is limited you may also want to enable indexer achnowledgement to prevent data lost in-flight.