Getting Data In

splunktcpin queue full what is the impact?

adityapavan18
Contributor

Hi

In my splunk environment i have around 50-60 instances of splunktcpin queue blocked?
what is the impact on my data if splunktcpin queue is blocked? Would i be losing some data forwarded from my universal forwarder?

WHen you say a queue is blocked, how long will the queue be blocked?

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi adityapavan18,

basically you can say that a queue is blocked until the congestion in the next queue is removed.
Most cases for blocked queues are either a temporary indexer overload, slow disks or forwarders sending too much data for what ever reason (some java log from a application gone crazy for example).

You can limit the forwarder to not sent too much data at once in limits.conf:

[thruput]

maxKBps = <integer>
* If specified and not zero, this limits the speed through the thruput processor to the specified rate in kilobytes per second.

additionally you can setup a persistent queue on the forwarder to prevent data loss.

Regarding the Indexer, you can follow this checklist about performance.

hope this helps ...

cheers, MuS

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...