Getting Data In

Server crashes when launching data integrator

vnetrebko
Engager

Hi! Is there any way to make data retrival rate slower? Something like 1h worth of data every 1m
When we are trying to save 30D data from our elastic(about 4.4m events) server makes huge network load spike and then stops responding.

Labels (2)
0 Karma

dural_yyz
Motivator

https://docs.splunk.com/Documentation/Splunk/9.3.0/Admin/Outputsconf

There are many options available in the outputs.conf.spec sheet.  You can start setting queue and buffers but be cautious that data in queues and buffers can age out and risk no ingestion.

The other thing is try setting compression to reduce the network traffic demands but it will increase the CPU demands on source and destination so make sure that you have cycles to spare.

Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...