Getting Data In

Where do I have to set persistent queue configuration in order to offload event on UF's disk?

brandy81
Path Finder

Hi, I am collecting event from UF to IDX. Sometimes events are missing due to network issue btw UF and IDX.
So I am trying to use persistent queue.
Now I am seeing this manual : https://docs.splunk.com/Documentation/Splunk/8.0.1/Data/Usepersistentqueues

I would like to write missing event on UF's disk when the network connection is disconnected.
And when the connection becomes normal, I want to forward those written event on disk to IDX.

Then, do I have to below inputs.conf setting on UF? or IDX?

[tcp://9994]
persistentQueueSize=100MB

Please help me out.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...