Getting Data In

Why are we seeing an issue with an EXTREMELY busy forwarder bogging down our indexers?

Path Finder

Recently, indexing from that particular forwarder has gotten to be even slower, sometimes falling hours behind. I'm curious as to what the recommendation from the community may be:

  1. Configure improved load balancing with props.conf with EVENT_BREAKER_ENABLE setting to true.
  2. Changing existing forceTimebasedAutoLB settings to a shorter interval
  3. Something else

Our version is 7.0.2

0 Karma


You'd have to create local/limits.conf and then set It to 0 if you want unlimited. You also may want to consider increasing various queues (parsing queue) if your dealing with a lot of data.

Last you may want to consider increasing the number of pipelines. Get some more firepower In there! Just know it comes at a cost on your remote system (system with the universal forwarder installed).

0 Karma

Path Finder

limits.conf doesn't exist in local. maxKBps = 0 is in limits.conf in default.

4 Indexers

1,322 KB/s
Total Indexing Rate - 331 KB/s
Average Indexing Rate - 264 KB/s

0 Karma

Ultra Champion

First we need to determine how much data this forwarder is pushing to the indexers...

0 Karma


Did you check to make sure the forwarder has not hit the throttle limits? maxKBps as per "maxKBps option and limiting a Forwarder's rate of thruput" or the limits.conf file

0 Karma
Get Updates on the Splunk Community!

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...

The Great Resilience Quest: 10th Leaderboard Update

The tenth leaderboard update (11.23-12.05) for The Great Resilience Quest is out >> As our brave ...