Getting Data In

nullqueue or nullQueue ?

yannK
Splunk Employee
Splunk Employee

I saw this in transforms.conf : should if be nullQueue or nullqueue ?

[send_to_nullqueue]
DEST_KEY = queue
REGEX    = .
FORMAT   = nullQueue
Tags (1)
1 Solution

lguinn2
Legend

nullQueue is the correct spelling.

View solution in original post

lguinn2
Legend

nullQueue is the correct spelling.

yannK
Splunk Employee
Splunk Employee

Thank you, I tested with the wrong one, and it created 2 lines in metrics, that look identical but are not.
`
10-02-2012 08:26:13.261 -0400 INFO Metrics - group=queue, name=nullqueue, max_size_kb=500, current_size_kb=0, current_size=0, largest_size=0, smallest_size=0
10-02-2012 08:26:13.261 -0400 INFO Metrics - group=queue, name=nullqueue, blocked=true, max_size_kb=500, current_size_kb=499, current_size=998, largest_size=998, smallest_size=998

and when the wrong queue one was full, my indexer was buster, unable to accept any data. So please use the correct nullQueue.
`

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...