I create a forwarder on a remote site. The speed of network is limited. I need transfer the event log in middle-night on the forwarder.
How can I configure the transfer start at middle-night, pause at six o'clock?
Thank you in advance.
Create a batch script that reduce the thruput during day time, and unleash the beast at night.
I assume that you are on windows
create %SPLUNK\_HOME%\etc\system\local\limits.conf_superslow
[thruput]
maxKBps=50
# default was 256
and create %SPLUNK\_HOME%\etc\system\local\limits.conf_superfast
[thruput]
maxKBps=0
# for unlimited
Then at night time run a batch using the windows scheduler (running under the correct user of course)
cp %SPLUNK_HOME%\etc\system\local\limits.conf_superfast %SPLUNK_HOME%\etc\system\local\limits.conf
%SPLUNK\_HOME%\bin\splunk restart
and in the morning
cp %SPLUNK_HOME%\etc\system\local\limits.conf_superslow %SPLUNK_HOME%\etc\system\local\limits.conf
%SPLUNK_HOME%\bin\splunk restart
@shizl, There are couple of ways to accomplish what your want or least come close, scripted input or oneshot. Please read my previous post. Hope this helps.
If your network is limited you may also want to enable indexer achnowledgement to prevent data lost in-flight.
collect and transfer cannot be scheduled then you will need to use a local cron job to stop & start splunk.
What do you mean? Configure what?
How to configure the forwarder or indexer without stop splunk?
How to configure the forwarder or indexer without stop splunk?