Monitoring Splunk

HEC Collector Cluster: Measuring Performance

amat
Explorer

I've been looking around how to measure and scale a Splunk HEC Collector cluster, but I cant seem to find direct answers.

I am trying to find a way to measure the performance of a HEC Collector and how to determine when a HEC Collector cluster needs to be scaled to accommodate more/less HEC requests. I understand that EPS ( events per second) can be measured but how does one determine if that number is too high or too low?

Currently, i have two Heavyforwarders that are acting as HEC Collectors behind a load balancer. I am trying to find out a good way to determine if this is enough or if another member needs to be added.

Appreciate the help!

0 Karma

PavelP
Motivator

Hello @amat

not quite what you asked: you can measure the indexing performance which includes HEC Collector latency. You can do this:

  • directly with metrics data or as diff between _indextime and _time
  • using Monitoring Console (MC)

Before you add more HEC Collectors, try to tune your setup:

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...