Getting Data In

Is it best practice to collect data from network drives using a heavy forwarder? I'm seeing performance issues.

dkeck
Influencer

Hello and good morning,

I have a heavy forwarder that takes inputs from several network drives and it's working fine so far.

The question I can't find an answer to in the Splunk docs is, is getting data from network drives best practice?

The thing is, I have performance problems. The data is indexed with a delay and I'm trying to figure out if maybe the network drives have a part in that.

Any assistance on this would be greatly appreciated. A link to a Splunk doc would be perfect.

Thank you

1 Solution

dkeck
Influencer

Thank you 🙂

I found a different failure, repsonsible for the delay. Thank you very much anyway.

Several Servers in the outputs.conf where not reachable, so splunk retried all the time.

View solution in original post

0 Karma

dkeck
Influencer

Thank you 🙂

I found a different failure, repsonsible for the delay. Thank you very much anyway.

Several Servers in the outputs.conf where not reachable, so splunk retried all the time.

0 Karma

JeffSchumacher
Engager

I started seeing massive delays (5+ minutes, sometimes 10) after upgrading to 6.3.0 (Also having this problem is 6.3.1). I have about 60 UNC paths that I'm monitoring.

Changing to use the Universal Forwarder on the source of the logs worked around the massive delay problem for us,

dkeck
Influencer

I would like to except your answer..but theres not button for it...sry

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...