Monitoring Splunk

HEC Collector Cluster: Measuring Performance

amat
Explorer

I've been looking around how to measure and scale a Splunk HEC Collector cluster, but I cant seem to find direct answers.

I am trying to find a way to measure the performance of a HEC Collector and how to determine when a HEC Collector cluster needs to be scaled to accommodate more/less HEC requests. I understand that EPS ( events per second) can be measured but how does one determine if that number is too high or too low?

Currently, i have two Heavyforwarders that are acting as HEC Collectors behind a load balancer. I am trying to find out a good way to determine if this is enough or if another member needs to be added.

Appreciate the help!

0 Karma

PavelP
Motivator

Hello @amat

not quite what you asked: you can measure the indexing performance which includes HEC Collector latency. You can do this:

  • directly with metrics data or as diff between _indextime and _time
  • using Monitoring Console (MC)

Before you add more HEC Collectors, try to tune your setup:

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...