Getting Data In

What is splunk's capacity for receiving UDP events/second?

Chris_R_
Splunk Employee
Splunk Employee

We have an index that gets around 2million events/hour and it seems not a sizable number of events are not making it from the manager to our splunk instance. At the very least we are talking about 60,000 events in a 24 hours period. This would seem to be beyond the normal expected loss for connectionless UDP. Is it possible splunk is being inundated with so many events that some are being discarded?

Tags (4)
1 Solution

Simeon
Splunk Employee
Splunk Employee

You can examine the performance of Splunk by examining the thruput for that particular input. Using UDP as the network protocol is not recommended if you are concerned about data loss. There is the following wiki topic that details tuning recommendations and some troubleshooting tips:

http://www.splunk.com/wiki/Community:UDPInputs

The capacity of a Splunk instance is mostly determined by the hardware. Our reference architecture (for handling 100 GB/day) is capable of handling peak thruput in excess of 3 MB/sec. I have seen up to 10 MB/sec in some cases.

View solution in original post

Simeon
Splunk Employee
Splunk Employee

You can examine the performance of Splunk by examining the thruput for that particular input. Using UDP as the network protocol is not recommended if you are concerned about data loss. There is the following wiki topic that details tuning recommendations and some troubleshooting tips:

http://www.splunk.com/wiki/Community:UDPInputs

The capacity of a Splunk instance is mostly determined by the hardware. Our reference architecture (for handling 100 GB/day) is capable of handling peak thruput in excess of 3 MB/sec. I have seen up to 10 MB/sec in some cases.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...