Getting Data In

Increase Throughput Limit on a Lightweight Forwarder

pj
Contributor

Quick question -

I realise that putting a forwarder into lightweight mode will automatically limit throughput by default to 256Kbps.

Can I add in a limits.conf entry to the etc/system/local folder on the forwarder and increase this limit to say 500Kbps?

e.g.

[thruput]
maxKBps = 500

Will this override the 256 limit in the lightweight forwarder or is the limit fixed, because it is lightweight or something?

Many thanks

1 Solution

bwooden
Splunk Employee
Splunk Employee

You are correct. Settings in local override settings in default. It is not fixed due to it being a light weight forwarder. It is simply a default value that can be overwritten as you mention. Splunk docs on configuration file precedence contain more details.

View solution in original post

bwooden
Splunk Employee
Splunk Employee

You are correct. Settings in local override settings in default. It is not fixed due to it being a light weight forwarder. It is simply a default value that can be overwritten as you mention. Splunk docs on configuration file precedence contain more details.

yannK
Splunk Employee
Splunk Employee

if ypu use this setting, it will be unlimited (as on heavy forwarders, and indexers)


[thruput]
maxKBps = 0

0 Karma

pj
Contributor

This fact should really be added to the documentation around the lightweight forwarder differences.

Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...