Hi All.
Hope everyone doing well.
we are sending data from demisto to Splunk. But here when data came to Splunk it is indexing cumulatively like yesterday we got 10 incidents and it was indexed yesterday. today 5 incidents and when indexing the data today it is indexing yesterday's 10 incidents along with todays 5 incident details. here we are getting the cumulative results. Kindly help me with the same.
Thanks In Advance
Balaji
Have you increased the thruput on your forwarder? It's set to 256kbs by default which can cause throttling if not increased.
Set the following in limits.conf to increase to unlimited (be sure to cycle Splunk for the change to take effect):
[thruput]
maxKBps = 0
https://docs.splunk.com/Documentation/Splunk/latest/Admin/Limitsconf
Hi Codebuilder,
Thanks for the reply.
Yes we have updated earlier itself. But the data indexing cumulatively.
Thanks & Regards,
Balaji