Getting Data In

Measuring thruput of heavy forwarders in a dashboard. Would using "metrics.log group=thruput name=thruput" add both input and output thruput to the final result?

mwdbhyat
Builder

Hi,

Quick question regarding metrics.log and a heavy forwarder (HF). I'm using a dashboard to measure the thruput on a few HF's and was curious if using metrics.log group=thruput name=thruput adds both input and output thruput to the final result ?

Thanks!

0 Karma

inventsekar
SplunkTrust
SplunkTrust

http://blogs.splunk.com/2008/05/15/forwarder-and-indexer-metrics/

Here’s a sample query that you can run on each indexer instance to get a report on thruput by each forwarding entity:

index=_internal metrics "group=tcpin_connections" | timechart span=30s avg(tcp_bps) by sourceHost

0 Karma

jlvix1
Communicator

Post one of your queries

0 Karma

koshyk
Super Champion

As per the thread : https://answers.splunk.com/answers/377028/how-to-configure-dmc-for-heavy-forwarder-monitorin.html an idea is to mark the heavyforwarder as an "indexer" in the DMC and DMC will all do it for you

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...