Security

Log latency

VijaySrrie
Builder

Hi Team,

We could see latency in logs

Log ingestion via - syslog

Network devices --> Syslog server --> splunk 

Using below query, we could see minimum 10 mins to maxminum 60 mins log latency

index="ABC" sourcetype="syslog" source="/syslog*" 
| eval indextime=strftime(_indextime,"%c")
| table _raw _time indextime



What should be our next steps to check where the latency is and how to fix it?

0 Karma
1 Solution

VijaySrrie
Builder

@KendallW 
INFO ThruputProcessor [2963 parsing] - Current data throughput (5125 kb/s) has reached maxKBps. As a result, data forwarding may be throttled. Consider increasing the value of maxKBps in limits.conf.

We will try increasing the limits.

View solution in original post

0 Karma

VijaySrrie
Builder

@KendallW 
INFO ThruputProcessor [2963 parsing] - Current data throughput (5125 kb/s) has reached maxKBps. As a result, data forwarding may be throttled. Consider increasing the value of maxKBps in limits.conf.

We will try increasing the limits.

0 Karma

KendallW
Contributor

Hi @VijaySrrie assuming you are collecting the logs on syslog server then forwarding to Splunk with a UF?
You can check if the UF is reaching its thruput limit which could cause indexing lag:

index=_internal sourcetype=splunkd component=ThruputProcessor "has reached maxKBps" 



Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...