Monitoring Splunk

Performance impact of connection refusals (Fwd --> Idx)

Builder

I have my forwarders sending data to an Indexer Cluster. And now I am introducing a new indexer in my env but not keeping it as part of the Cluster.
My need is that I'll not always be running this new Idx, since I will use this only for special needs (say testing purposes). Now, whenever I keep this Indexer box down, I get thousands of Connection refusal errors from all forwarders which is expected as they keep trying to connect to this box as well.

Now, I want to know if these enormous attempts for connections resulting into errors cause any performance degradation ? How ? And if I can measure it ?

SplunkTrust
SplunkTrust

Sure they can impact performance on the network if it's already saturated.

How many attempts are you considering "enormous"?

0 Karma