Getting Data In

How to set the exec queue size in server.conf to increase perfmon inputs?

alvn_sulendra
Explorer

We are trying to increase the size of exec queue since we check that for Perfmon and Wineventlog, it stores the queue there. We don't want to increase the parsingQueue since there are other data that we are forwarding.

I try to set in server.conf:

[queue=exec]
maxSize = 10MB

However, when we monitored the metric.log, the max_size_kb is still 500KB as it original were.

The Forwarder we use is Universal Forwarder 6.4.1

Thanks

0 Karma

lguinn2
Legend

First, you should not be setting queue sizes without consulting Splunk Support. Second, these queue sizes do not apply to the Universal Forwarder. These are index-time queues and exist only on the indexers.

If you are having problems with the performance of perfmon, you should take whatever action is appropriate at the Windows operating system level.

Be aware that WMI is the "Windows Management Interface" not the "Windows Monitoring Interface." It is not intended for high-volume monitoring.

0 Karma

alvn_sulendra
Explorer

Hi Iguinn,

thank you for the answer and recommendation. Currently we are monitoring Perfmon and Wineventlog
the reason for us trying to increase the queue is to ensure that we can still get the data for certain duration if the indexer is down. And currently the option for high availability is not viable because of resource constraint. Thanks

regards,
Alvin

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...