Getting Data In

Is it best practice to collect data from network drives using a heavy forwarder? I'm seeing performance issues.

dkeck
Influencer

Hello and good morning,

I have a heavy forwarder that takes inputs from several network drives and it's working fine so far.

The question I can't find an answer to in the Splunk docs is, is getting data from network drives best practice?

The thing is, I have performance problems. The data is indexed with a delay and I'm trying to figure out if maybe the network drives have a part in that.

Any assistance on this would be greatly appreciated. A link to a Splunk doc would be perfect.

Thank you

1 Solution

dkeck
Influencer

Thank you 🙂

I found a different failure, repsonsible for the delay. Thank you very much anyway.

Several Servers in the outputs.conf where not reachable, so splunk retried all the time.

View solution in original post

0 Karma

dkeck
Influencer

Thank you 🙂

I found a different failure, repsonsible for the delay. Thank you very much anyway.

Several Servers in the outputs.conf where not reachable, so splunk retried all the time.

0 Karma

JeffSchumacher
Engager

I started seeing massive delays (5+ minutes, sometimes 10) after upgrading to 6.3.0 (Also having this problem is 6.3.1). I have about 60 UNC paths that I'm monitoring.

Changing to use the Universal Forwarder on the source of the logs worked around the massive delay problem for us,

dkeck
Influencer

I would like to except your answer..but theres not button for it...sry

0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...