Getting Data In

splunktcpin queue full what is the impact?

adityapavan18
Contributor

Hi

In my splunk environment i have around 50-60 instances of splunktcpin queue blocked?
what is the impact on my data if splunktcpin queue is blocked? Would i be losing some data forwarded from my universal forwarder?

WHen you say a queue is blocked, how long will the queue be blocked?

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi adityapavan18,

basically you can say that a queue is blocked until the congestion in the next queue is removed.
Most cases for blocked queues are either a temporary indexer overload, slow disks or forwarders sending too much data for what ever reason (some java log from a application gone crazy for example).

You can limit the forwarder to not sent too much data at once in limits.conf:

[thruput]

maxKBps = <integer>
* If specified and not zero, this limits the speed through the thruput processor to the specified rate in kilobytes per second.

additionally you can setup a persistent queue on the forwarder to prevent data loss.

Regarding the Indexer, you can follow this checklist about performance.

hope this helps ...

cheers, MuS

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...