Getting Data In

What is the significance of log file size for splunk ingestion?

rgchandrasekara
Observer

If the file size in GB's would create any issue in indexing performance?

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @rgchandrasekara,

indexing performaces, and the consequent resources (CPUs) and number of Indexers to use, depend on the volume of logs to index.

Think that an indexer (with the normal hardware reference) can usually index until 200 GB/day, if you haven't ES ot ITSI.

Ciao.

Giuseppe

0 Karma

rgchandrasekara
Observer

thank you @gcusello for the quick response.

I would like to know single log file being monitored and it does not have any rotation policy. So as time goes file size grow into GB's.

Will the CRC check get time delay due to the file size?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @rgchandrasekara,

Splunk index ony the new logs, even if in another file with a different name, with the ony exception if you use crcSal = <SOURCE>: it doesn't index twice old logs.

Ciao.

Giuseppe

0 Karma

rgchandrasekara
Observer

@gcusello : my query specific to " Time it takes for CRC check - will it get affected if the file size grow into GB's?"

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @rgchandrasekara ,

not in my knowledge.

if you use crcSal the check is on filename, otherwise without it the check is on the first 256 chars.

Ciao.

Giuseppe

0 Karma

rgchandrasekara
Observer

Thanks @gcusello 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @rgchandrasekara,

if one answer solves your need, please accept one answer for the other people of Community or tell me how I can help you.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...