Monitoring Splunk

Performance impact of connection refusals (Fwd --> Idx)


I have my forwarders sending data to an Indexer Cluster. And now I am introducing a new indexer in my env but not keeping it as part of the Cluster.
My need is that I'll not always be running this new Idx, since I will use this only for special needs (say testing purposes). Now, whenever I keep this Indexer box down, I get thousands of Connection refusal errors from all forwarders which is expected as they keep trying to connect to this box as well.

Now, I want to know if these enormous attempts for connections resulting into errors cause any performance degradation ? How ? And if I can measure it ?


Sure they can impact performance on the network if it's already saturated.

How many attempts are you considering "enormous"?

0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes
and swag!