I have a RH EL6 system receiving udp 514 traffic from network equipment and writing to a file /data/log/messages.
The inbound message traffic is very high but the system is writing to the file just fine. I installed a universal forwarder (4.3.3) and through our deployment server push down an app to monitor that file and send it to our 10 indexers.
In the three hours since implementing this, only the first 50 minutes of logs have been indexed.
Looking at netstat -pn we can see that the splunk forwarder connecting to one of our indexers at a time. Could this be the bottleneck? Any suggestions on how to improve the performance.
disabled = false
source = network
sourcetype = syslog
index = network