Getting Data In

Throttle speed when Splunk Forwarder starts up?

Dark_Ichigo
Builder

When starting up the Splunk forwarder, I have noticed that there is a CPU spike that hits, but this is only when at start-up, my question is, is there any network throttling capability that Splunk uses to prevent a large CPU spike at start up?, or is this something I really shouldn't worry about?

I'm not sure if the CPU spike is related to network activity during splunk start-up, Im not too sure if the Splunk Forwarder increases network activity when it first starts up and then gradually decreases when start-up is complete?, or is this when it first when it establishes a connection with the Splunk index server?

0 Karma

yannK
Splunk Employee
Splunk Employee

The universal and lightweight forwarder have a network threshold of 256KBps (see thruput in limits.conf).

You can observe a network spike at the start but it stabilized after a minute.
But the Cpu spike may also be the scan of all the monitored files to check the modifications.

0 Karma

Dark_Ichigo
Builder

Thanks, funny thing is that its currently set to 0 in limits.conf, If this will indeed limit how much can be forwarded over the network at once, then my work here is done 🙂

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...