Getting Data In

Splunk HF - Typing Queue full but CPU of the machine is low

GaetanVP
Contributor

Hello Splunkers,

I am currently having parsing problems with my Splunk Heavy Forwarder.
I know I have heavy regex  that are causing Typing Queue problems, but I do not understand why "Splunk is not taking more CPU" on my machine (CPU is always around 10-15%)

Thanks a lot,

GaetanVP  

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @GaetanVP,

on Heavy Forwarder you can use parallel pipeline to optimize your CPU use.

here you can find indications for indexers, but it's the same for HFs: https://docs.splunk.com/Documentation/Splunk/9.0.3/Indexer/Pipelinesets

In few words, you have to put in [general] stanza of server.conf:

parallelIngestionPipelines = 2

You cannot put an higher value event if you have more CPUs.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @GaetanVP,

on Heavy Forwarder you can use parallel pipeline to optimize your CPU use.

here you can find indications for indexers, but it's the same for HFs: https://docs.splunk.com/Documentation/Splunk/9.0.3/Indexer/Pipelinesets

In few words, you have to put in [general] stanza of server.conf:

parallelIngestionPipelines = 2

You cannot put an higher value event if you have more CPUs.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...

Splunk and Fraud

Watch Now!Watch an insightful webinar where we delve into the innovative approaches to solving fraud using the ...