Getting Data In

Throttle speed when Splunk Forwarder starts up?

Dark_Ichigo
Builder

When starting up the Splunk forwarder, I have noticed that there is a CPU spike that hits, but this is only when at start-up, my question is, is there any network throttling capability that Splunk uses to prevent a large CPU spike at start up?, or is this something I really shouldn't worry about?

I'm not sure if the CPU spike is related to network activity during splunk start-up, Im not too sure if the Splunk Forwarder increases network activity when it first starts up and then gradually decreases when start-up is complete?, or is this when it first when it establishes a connection with the Splunk index server?

0 Karma

yannK
Splunk Employee
Splunk Employee

The universal and lightweight forwarder have a network threshold of 256KBps (see thruput in limits.conf).

You can observe a network spike at the start but it stabilized after a minute.
But the Cpu spike may also be the scan of all the monitored files to check the modifications.

0 Karma

Dark_Ichigo
Builder

Thanks, funny thing is that its currently set to 0 in limits.conf, If this will indeed limit how much can be forwarded over the network at once, then my work here is done 🙂

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...