Getting Data In

Optimum payload size for ingesting events via splunk HEC

kkarthik_splunk
Splunk Employee
Splunk Employee

I am trying to ingest data into Splunk via Splunk HEC using a python script. I am also sending the data in batches.

What should be the optimum size of the payload(data) that can be sent in a single post request to optimize the performance of the ingestion script?

Labels (1)
0 Karma

gjanders
SplunkTrust
SplunkTrust

There is a Splunk conf presentation that covers this but I'm unsure which one. It will be on https://conf.splunk.com/watch/conf-online.html

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...