Getting Data In

Low ingestion thruput without queues blocked.

hrawat
Splunk Employee
Splunk Employee

Problem: 

Indexing throughput drops linearly when new data sources/forwarders/apps are added.

hrawat
Splunk Employee
Splunk Employee

Indexing throughput drops linearly when the tuple( combination of the cross product of source, sourcetype and host) increases( Anything > 10k).
Run following search to find if you see channel explosion
index=_internal source=*metrics.log new_channels | timechart max(new_channels)

Each tuple can generate several pipeline input channels. Channel churn puts significant pause in the ingestion pipeline where managing these channels takes significantly long time for pipeline processors and thus ingest less data.

Solutions
For HEC INPUTS :
Increase following two on IDX ( or which ever layer the explosion is). Generally these values must be > 2 times max(new_channels)
[input_channels]
max_inactive =
* Internal setting, do not change unless instructed to do so by Splunk
Support.

lowater_inactive =
* Internal setting, do not change unless instructed to do so by Splunk
Support.

For S2S(UF/HF) INPUTS : Increase following on IDX ( or which ever layer the explosion is)
max_inactive =
* Internal setting, do not change unless instructed to do so by Splunk Support.

On Forwarding side(all UF/HFs) increase
autoLBFrequency upto 180 sec.

to4kawa
Ultra Champion

over splunk ver 8:

| tstats max(PREFIX("new_channels=")) where index=_internal source=*metrics.log by _time
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...