Getting Data In

Performance Tuning Suggestions for TCP Syslog Running on Server 2012

jodros
Builder

I know this is not a Splunk specific question, however I have asked a similar question in the past about tuning for UDP syslog on linux. I need to know what to watch out for when dealing with high volumes and bursts of TCP syslog. This is a Server 2012 VM using vmxnet3 drivers. I have maxed out the Small/Large RX Buffers as well as RX Ring #1/#2 Size. I have also tested enabling/disabling LSO V2 (IPv4) but that had little impact.

Any assistance would be appreciated.

Thanks

0 Karma
1 Solution

jodros
Builder

Resolved issue with our RHEL UDP syslog environment. WinOS was not able to increase receive buffers to amount that was required.

View solution in original post

0 Karma

jodros
Builder

Resolved issue with our RHEL UDP syslog environment. WinOS was not able to increase receive buffers to amount that was required.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...