Getting Data In

Measuring thruput of heavy forwarders in a dashboard. Would using "metrics.log group=thruput name=thruput" add both input and output thruput to the final result?



Quick question regarding metrics.log and a heavy forwarder (HF). I'm using a dashboard to measure the thruput on a few HF's and was curious if using metrics.log group=thruput name=thruput adds both input and output thruput to the final result ?


0 Karma

Super Champion

Here’s a sample query that you can run on each indexer instance to get a report on thruput by each forwarding entity:

index=_internal metrics "group=tcpin_connections" | timechart span=30s avg(tcp_bps) by sourceHost

0 Karma


Post one of your queries

0 Karma

Super Champion

As per the thread : an idea is to mark the heavyforwarder as an "indexer" in the DMC and DMC will all do it for you

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!