Getting Data In

What is splunk's capacity for receiving UDP events/second?

Chris_R_
Splunk Employee
Splunk Employee

We have an index that gets around 2million events/hour and it seems not a sizable number of events are not making it from the manager to our splunk instance. At the very least we are talking about 60,000 events in a 24 hours period. This would seem to be beyond the normal expected loss for connectionless UDP. Is it possible splunk is being inundated with so many events that some are being discarded?

Tags (4)
1 Solution

Simeon
Splunk Employee
Splunk Employee

You can examine the performance of Splunk by examining the thruput for that particular input. Using UDP as the network protocol is not recommended if you are concerned about data loss. There is the following wiki topic that details tuning recommendations and some troubleshooting tips:

http://www.splunk.com/wiki/Community:UDPInputs

The capacity of a Splunk instance is mostly determined by the hardware. Our reference architecture (for handling 100 GB/day) is capable of handling peak thruput in excess of 3 MB/sec. I have seen up to 10 MB/sec in some cases.

View solution in original post

Simeon
Splunk Employee
Splunk Employee

You can examine the performance of Splunk by examining the thruput for that particular input. Using UDP as the network protocol is not recommended if you are concerned about data loss. There is the following wiki topic that details tuning recommendations and some troubleshooting tips:

http://www.splunk.com/wiki/Community:UDPInputs

The capacity of a Splunk instance is mostly determined by the hardware. Our reference architecture (for handling 100 GB/day) is capable of handling peak thruput in excess of 3 MB/sec. I have seen up to 10 MB/sec in some cases.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...