Monitoring Splunk

Performance impact of connection refusals (Fwd --> Idx)


I have my forwarders sending data to an Indexer Cluster. And now I am introducing a new indexer in my env but not keeping it as part of the Cluster.
My need is that I'll not always be running this new Idx, since I will use this only for special needs (say testing purposes). Now, whenever I keep this Indexer box down, I get thousands of Connection refusal errors from all forwarders which is expected as they keep trying to connect to this box as well.

Now, I want to know if these enormous attempts for connections resulting into errors cause any performance degradation ? How ? And if I can measure it ?


Sure they can impact performance on the network if it's already saturated.

How many attempts are you considering "enormous"?

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!