Getting Data In

We are sending data to Splunk from demisto. But the data indexing cumulatively

Chintham
Observer

Hi All. 

Hope everyone doing well. 

we are sending data from demisto to Splunk. But here when data came to Splunk it is indexing cumulatively like yesterday we got 10 incidents and it was indexed yesterday. today 5 incidents and when indexing the data today it is indexing yesterday's 10 incidents along with todays 5 incident details. here we are getting the cumulative results. Kindly help me with the same. 

Thanks In Advance

Balaji

 

Labels (3)
0 Karma

codebuilder
Influencer

Have you increased the thruput on your forwarder? It's set to 256kbs by default which can cause throttling if not increased.

Set the following in limits.conf to increase to unlimited (be sure to cycle Splunk for the change to take effect):

[thruput]
maxKBps = 0

https://docs.splunk.com/Documentation/Splunk/latest/Admin/Limitsconf

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

Chintham
Observer

Hi Codebuilder, 

Thanks for the reply. 

Yes we have updated earlier itself. But the data indexing cumulatively. 

 

Thanks & Regards,

Balaji 

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...