Getting Data In

Optimum payload size for ingesting events via splunk HEC

kkarthik_splunk
Splunk Employee
Splunk Employee

I am trying to ingest data into Splunk via Splunk HEC using a python script. I am also sending the data in batches.

What should be the optimum size of the payload(data) that can be sent in a single post request to optimize the performance of the ingestion script?

Labels (1)
0 Karma

gjanders
SplunkTrust
SplunkTrust

There is a Splunk conf presentation that covers this but I'm unsure which one. It will be on https://conf.splunk.com/watch/conf-online.html

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...