Monitoring Splunk

Splunk Load Balancer Forwarder Performance Problem

clyde772
Communicator

Hey Splunkers,

Anyone who knows about setting up splunk forwarder as a load balancer to aggregate lower forwarder?

We have an issue where we are aggregating all lower forwarder traffic to a forwarder set-up as a load balanced forwarder. In this scenario, we have bottle neck at the aggregated forwarder where data is being queued not processing lower forwarder traffice fast enough. How can we set-up that aggregating LB forwarder to process at it's max to process all traffic as fast as possible.

Is there limits on max amount of traffic a forwarder can process as LB forwarder? we have looked at the limits.conf for thruput option which set to "0" to minimize any limits.

Thanks in advance~!

Tags (2)
0 Karma

MarioM
Motivator

have you looked into the maxQueueSize attribute in outputs.conf or [queue] maxSize in server.conf ?

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...