Getting Data In

Splunk Indexing rate in extremely high

Mescudi
Explorer

Hello,

We are using a Splunk enterprise license currently with 24 gb of license space. Our problem is that are indexing rate is above 1000kb/s and maxing out our license usage. We cannot upgrade our license usage due to policies. Our usage reports were not configured, so we cannot see anything through monitoring report. Is there something possible in the inputs or config files that is causing are machines to send such a large amount of info to splunk? 

Any help would be appreciated 

thanks

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @Mescudi ... the DMC console got some dashboards(i am not sure of the dashboards, as currently i dont have access to a DMC) that will tell you which UF's are sending high amounts of data/logs. you should find those UF's and troubleshoot the inputs.conf.. you may not need some logs i think, but mistakenly configured. 

for example, on UF inputs.conf, if /tmp/* is added for monitoring (lets assume the "*" was added by mistake), then every file under the tmp directory will be monitored. 

you can search for some search queries... Splunk license usage by UFs.

Let us know how it goes.. we will help you to troubleshoot this issue, thanks. 

Mescudi
Explorer

Okay when searching through our DMC I See a couple machines and our Splunk server itself causing high amounts of events. I went to check one of the machines and they don't have an inputs.conf file in the universal forwarder file. Could this be the problem? 

0 Karma

Mescudi
Explorer

It also seems to be coming from metric logs, I'm just confused as to what is causing such a high index rate when before it was low. We just hit 97% on our license usage. 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...

Keep the Learning Going with the New Best of .conf Hub

Hello Splunkers, With .conf26 getting closer, there’s already a lot of excitement building around this year’s ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...