Getting Data In

parallelIngestionPipelines on heavy forwarder

mraudaschl
Loves-to-Learn

hi,
we have activated parallelIngestionPipelines (set to 2) due to blocked queues on a heavy forwarder. After adding another pipeline, there is no change in the congestion and it seems that only one pipeline is used by Splunk.
Pipeline 0 still gets blocked and filled to 100% and pipeline 1 processes only on rare occasions, usually filled to 0 %. Any idea what could cause this unexptected behavior?

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...