Getting Data In

Where do I have to set persistent queue configuration in order to offload event on UF's disk?

brandy81
Path Finder

Hi, I am collecting event from UF to IDX. Sometimes events are missing due to network issue btw UF and IDX.
So I am trying to use persistent queue.
Now I am seeing this manual : https://docs.splunk.com/Documentation/Splunk/8.0.1/Data/Usepersistentqueues

I would like to write missing event on UF's disk when the network connection is disconnected.
And when the connection becomes normal, I want to forward those written event on disk to IDX.

Then, do I have to below inputs.conf setting on UF? or IDX?

[tcp://9994]
persistentQueueSize=100MB

Please help me out.

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...