Splunk Cloud Platform

Splunk Forwarders Buffer size and best practices?

SplunkExplorer
Contributor

Hi Splunkers, I have some doubts about forwarder buffer, both universal and heavy.

The starting point is this: I know that, if an indexer goes down and it is receiving data by a UF,  this has a buffering mechanism to store data and send them to proper destination once it is up and running again. If I'm not wrong, the limits of this buffer can be set on a config file (I don't remeber well wich one). Now, the question are:

1. Even if the answer can be obvious, this mechanism is already available for HF?
2. How can I decide the maximum size of my buffer? is there a pre set limit or it depends on my environments?

Labels (1)
0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @SplunkExplorer 

theses attributes in outputs.conf will take care these 

maxQueueSize
autoLBFrequency
autoLBVolume
useAck

https://docs.splunk.com/Documentation/Splunk/8.2.7/Admin/Outputsconf 

SanjayReddy_0-1666883578695.png

SanjayReddy_1-1666883655795.png

SanjayReddy_2-1666883753342.png

 

 

 

0 Karma

SplunkExplorer
Contributor

Hi @SanjayReddy , thanks a lot. I didn't remember about the auto fields, I got memories only about useack and maxqueue size, very usefull.

About the max queue size, are there any souces I can use to understand the best/max value I can set in my environments? I ask this because my final question is: what is the max value I can set in maxQueueSize It depends by my hardware availability or there a limit I cannot overwhelm? 

 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...