Getting Data In

Performance Tuning Suggestions for TCP Syslog Running on Server 2012

jodros
Builder

I know this is not a Splunk specific question, however I have asked a similar question in the past about tuning for UDP syslog on linux. I need to know what to watch out for when dealing with high volumes and bursts of TCP syslog. This is a Server 2012 VM using vmxnet3 drivers. I have maxed out the Small/Large RX Buffers as well as RX Ring #1/#2 Size. I have also tested enabling/disabling LSO V2 (IPv4) but that had little impact.

Any assistance would be appreciated.

Thanks

0 Karma
1 Solution

jodros
Builder

Resolved issue with our RHEL UDP syslog environment. WinOS was not able to increase receive buffers to amount that was required.

View solution in original post

0 Karma

jodros
Builder

Resolved issue with our RHEL UDP syslog environment. WinOS was not able to increase receive buffers to amount that was required.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Developer Spotlight with Mika Borner

From Hackathon Winner to Enterprise Leader    Mika Borner, CEO and Founder of Datapunctum AG, has been ...

Continue Your Federation Journey: Join Session 3 of the Bootcamp Series

To help practitioners build a stronger foundation, we launched the Data Management & Federation ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...