Getting Data In

increasing maxKBPS for only one splunk forwarder host

kannu
Communicator

Hi Splunkers ,

I am getting this splunkd log entry in only one splunk forwarder .

05-09-2018 08:11:39.579 +0000 INFO ThruputProcessor - Current data throughput (258 kb/s) has reached maxKBps. As a result, data forwarding may be throttled. Consider increasing the value of maxKBps in limits.conf.

Please let me know how to solve this only for particular splunk forwarder . For doing only for one splunk forwarder can i mention the below entry in splunk forwarder for which i want or do i need to mention that in indexer (but how to mention that in indexer only for one splunk forwarder host not for all)

[thruput]
# means unlimited
maxKBps = 0

0 Karma
1 Solution

FrankVl
Ultra Champion

You configure that limit in the limits.conf on the respective forwarder, not the indexer.

View solution in original post

0 Karma

FrankVl
Ultra Champion

You configure that limit in the limits.conf on the respective forwarder, not the indexer.

0 Karma

cpetterborg
SplunkTrust
SplunkTrust

If you only want it on ONE forwarder, be sure to put it in a local/limits.conf file, to have the deployment server send the configuration to only the forwarder that you want.

0 Karma

ddrillic
Ultra Champion

Please be careful with opening it up. The forwarder might not be stable. You probably should check first the indexing latency for the past week or so, and determine if you truly have a problem...

0 Karma

xpac
SplunkTrust
SplunkTrust

This is also only a problem if it happens constantly. If you only have it happen a few times, it might just be fluctuation in data input.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...