Getting Data In

Server crashes when launching data integrator

vnetrebko
Engager

Hi! Is there any way to make data retrival rate slower? Something like 1h worth of data every 1m
When we are trying to save 30D data from our elastic(about 4.4m events) server makes huge network load spike and then stops responding.

Labels (2)
0 Karma

dural_yyz
Motivator

https://docs.splunk.com/Documentation/Splunk/9.3.0/Admin/Outputsconf

There are many options available in the outputs.conf.spec sheet.  You can start setting queue and buffers but be cautious that data in queues and buffers can age out and risk no ingestion.

The other thing is try setting compression to reduce the network traffic demands but it will increase the CPU demands on source and destination so make sure that you have cycles to spare.

Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...