Getting Data In

Splunk Indexing rate in extremely high

Mescudi
Explorer

Hello,

We are using a Splunk enterprise license currently with 24 gb of license space. Our problem is that are indexing rate is above 1000kb/s and maxing out our license usage. We cannot upgrade our license usage due to policies. Our usage reports were not configured, so we cannot see anything through monitoring report. Is there something possible in the inputs or config files that is causing are machines to send such a large amount of info to splunk? 

Any help would be appreciated 

thanks

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @Mescudi ... the DMC console got some dashboards(i am not sure of the dashboards, as currently i dont have access to a DMC) that will tell you which UF's are sending high amounts of data/logs. you should find those UF's and troubleshoot the inputs.conf.. you may not need some logs i think, but mistakenly configured. 

for example, on UF inputs.conf, if /tmp/* is added for monitoring (lets assume the "*" was added by mistake), then every file under the tmp directory will be monitored. 

you can search for some search queries... Splunk license usage by UFs.

Let us know how it goes.. we will help you to troubleshoot this issue, thanks. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !

Mescudi
Explorer

Okay when searching through our DMC I See a couple machines and our Splunk server itself causing high amounts of events. I went to check one of the machines and they don't have an inputs.conf file in the universal forwarder file. Could this be the problem? 

0 Karma

Mescudi
Explorer

It also seems to be coming from metric logs, I'm just confused as to what is causing such a high index rate when before it was low. We just hit 97% on our license usage. 

0 Karma
Get Updates on the Splunk Community!

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...

Stay Connected: Your Guide to October Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...