Getting Data In

How to set the exec queue size in server.conf to increase perfmon inputs?

alvn_sulendra
Explorer

We are trying to increase the size of exec queue since we check that for Perfmon and Wineventlog, it stores the queue there. We don't want to increase the parsingQueue since there are other data that we are forwarding.

I try to set in server.conf:

[queue=exec]
maxSize = 10MB

However, when we monitored the metric.log, the max_size_kb is still 500KB as it original were.

The Forwarder we use is Universal Forwarder 6.4.1

Thanks

0 Karma

lguinn2
Legend

First, you should not be setting queue sizes without consulting Splunk Support. Second, these queue sizes do not apply to the Universal Forwarder. These are index-time queues and exist only on the indexers.

If you are having problems with the performance of perfmon, you should take whatever action is appropriate at the Windows operating system level.

Be aware that WMI is the "Windows Management Interface" not the "Windows Monitoring Interface." It is not intended for high-volume monitoring.

0 Karma

alvn_sulendra
Explorer

Hi Iguinn,

thank you for the answer and recommendation. Currently we are monitoring Perfmon and Wineventlog
the reason for us trying to increase the queue is to ensure that we can still get the data for certain duration if the indexer is down. And currently the option for high availability is not viable because of resource constraint. Thanks

regards,
Alvin

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...