Getting Data In

SC4S: avoid sending metrics to Splunk

pepitogrillospl
Loves-to-Learn Lots

Hi all,

I am very new to Splunk and trying to avoid sending metrics to Splunk from the sc4s container.

Memory consumption is really growing to > 250Mb and we use sc4s only for sending ~100 lines every 10m, so  metrics is really not necessary for us.

I have tried to set syslog-ng source s_internal  to a null destination but cant make it work.

Any advice would be greatly appreciated.

Thank you very much

Daniel

Labels (1)
0 Karma

pepitogrillospl
Loves-to-Learn Lots

Hi,

Thank you for your aswer.

I'm trying to prevent SC4S to send via HEC syslog-ng logs, metrics and any other traffic besides the actual logs becase we have a low ressources environment.

In /opt/sc4s/local/config/destinations/block_me.conf:

destination d_block_metrics {
file("/dev/null");
};

And in /opt/sc4s/local/config/log_paths/block_me.conf:

log {
source(s_internal);
source(s_system);
#destination(d_hec_debug);
destination(d_block_metrics);

flags(final);
};

I guess I'm doing something wrong because even with flags(final); all metrics and errors are still being sent to Splunk.

I just need to restrict  ressources because used memory grows uncontrollably until it reaches the 256Mb allocated to the container.

Thank's a lot

Daniel

0 Karma

m_pham
Splunk Employee
Splunk Employee

I have a couple of questions:

- Are you trying to get rid of the the metrics data from Splunk's metrics.log?

- Can you post the props and transforms config that you tried?

What you're trying to do may not "fix" the memory utilization on your container.

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...