Getting Data In

Is it best practice to collect data from network drives using a heavy forwarder? I'm seeing performance issues.

dkeck
Influencer

Hello and good morning,

I have a heavy forwarder that takes inputs from several network drives and it's working fine so far.

The question I can't find an answer to in the Splunk docs is, is getting data from network drives best practice?

The thing is, I have performance problems. The data is indexed with a delay and I'm trying to figure out if maybe the network drives have a part in that.

Any assistance on this would be greatly appreciated. A link to a Splunk doc would be perfect.

Thank you

1 Solution

dkeck
Influencer

Thank you 🙂

I found a different failure, repsonsible for the delay. Thank you very much anyway.

Several Servers in the outputs.conf where not reachable, so splunk retried all the time.

View solution in original post

0 Karma

dkeck
Influencer

Thank you 🙂

I found a different failure, repsonsible for the delay. Thank you very much anyway.

Several Servers in the outputs.conf where not reachable, so splunk retried all the time.

0 Karma

JeffSchumacher
Engager

I started seeing massive delays (5+ minutes, sometimes 10) after upgrading to 6.3.0 (Also having this problem is 6.3.1). I have about 60 UNC paths that I'm monitoring.

Changing to use the Universal Forwarder on the source of the logs worked around the massive delay problem for us,

dkeck
Influencer

I would like to except your answer..but theres not button for it...sry

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...