Getting Data In

wheater splunk forwarder can compress data brfore forward

perlish
Communicator

Hi, I use splunk forwarder to forward data.
But the data was too much.
I want compress data before forward, wheather splunk support this?

Thank you

Tags (2)
0 Karma

DaveSavage
Builder

Perlish - have you considered zip'ing the files and then using a heavy forwarder to send them to your back end indexer?
There are quite a few threads here which discuss it, not least being: http://splunk-base.splunk.com/answers/52976/indexing-log-files-which-are-in-zip-format
Good luck. I'm still struggling to get my head around the quantities you must be talking about!
Br
Dave

0 Karma

Ayn
Legend

Docs?

http://docs.splunk.com/Documentation/Splunk/5.0/Deploy/Configureforwarderswithoutputs.confd#Forwardi...

 compressed     false   global or target group stanza   Specifies whether the forwarder sends compressed data. 

MuS
SplunkTrust
SplunkTrust

hi perlish

if I understand your request correct, you want to filter out unneeded data on the forwarder, right?
if so, you can setup a so call heavy forwarder and setup filters and routes on it.

Filters and routes could also be setup on the indexer.

cheers,
MuS

0 Karma

kristian_kolb
Ultra Champion

Are you saying that you need sustained data transfer rates of 20 MB/s? That's just over 1,7 TB per day. Seriously, that is a LOT.

With those requirements (and that kind of license), I believe that Splunk Support will help you out. File a support case at splunk.com/support

0 Karma

perlish
Communicator

Everyday,every second,i need forward data,the rate will be 20M/s, So if i limit rate, i can`t forward all data in oneday。

0 Karma

MuS
SplunkTrust
SplunkTrust

when you are saying you are loosing data, what kind of data is it and why does it get lost if it is not forwarded with in one day?

0 Karma

perlish
Communicator

yes.
It is.

0 Karma

MuS
SplunkTrust
SplunkTrust

and you really need every single bit of the data you are forwarding?

0 Karma

perlish
Communicator

Because if I dont limit, the rate will be 20M/s
If i limit, for example limit 10M/s.
I can
t finished forward in everyday.

0 Karma

MuS
SplunkTrust
SplunkTrust

why should this happen?

0 Karma

perlish
Communicator

But if i limit the rate, the data will loss.

0 Karma

MuS
SplunkTrust
SplunkTrust

you could limit the transfer rate on the forwarder likt this http://splunk-base.splunk.com/answers/52066/data-transfer-rate-between-forward-and-indexer
but I'm not aware of any compress feature.

0 Karma

perlish
Communicator

Oh,sorry, it`s my fault

I want to compress data.

Sorry.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...