Monitoring Splunk

HEC Collector Cluster: Measuring Performance

amat
Explorer

I've been looking around how to measure and scale a Splunk HEC Collector cluster, but I cant seem to find direct answers.

I am trying to find a way to measure the performance of a HEC Collector and how to determine when a HEC Collector cluster needs to be scaled to accommodate more/less HEC requests. I understand that EPS ( events per second) can be measured but how does one determine if that number is too high or too low?

Currently, i have two Heavyforwarders that are acting as HEC Collectors behind a load balancer. I am trying to find out a good way to determine if this is enough or if another member needs to be added.

Appreciate the help!

0 Karma

PavelP
Motivator

Hello @amat

not quite what you asked: you can measure the indexing performance which includes HEC Collector latency. You can do this:

  • directly with metrics data or as diff between _indextime and _time
  • using Monitoring Console (MC)

Before you add more HEC Collectors, try to tune your setup:

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...