Splunk Dev

Flushing and writing to Socket using javasdk

preben12
Communicator

Hi

I'm using the javasdk to create a Socket connection to a splunk index for posting events in a long running process.

The socket connection is kept open for the time the process is running, but I'm not able to see any events using the dashboard before the process is terminated, and the socket connection thereby is closed.
I have set tcp_nodelay to true, and flush after each write, but it doesn't seem to make any difference.

Is there any way to overcome this limitation without closing the socket after each write ?

Tags (1)
0 Karma
1 Solution

Damien_Dallimor
Ultra Champion

If you are using the Receiver attach() method , this uses the receivers/stream REST endpoint in Splunk. There has always been some buffering on the Splunk side , it seems to be around 1MB before the events start to get index in my fuzzy tests , or closing the socket will also flush the buffer.

If you are using the TCPInput attach() method , then the events should show up in Splunk immediately. I recommend this approach.The main difference being that you'll need to setup a TCP Input in Splunk first.

View solution in original post

Damien_Dallimor
Ultra Champion

If you are using the Receiver attach() method , this uses the receivers/stream REST endpoint in Splunk. There has always been some buffering on the Splunk side , it seems to be around 1MB before the events start to get index in my fuzzy tests , or closing the socket will also flush the buffer.

If you are using the TCPInput attach() method , then the events should show up in Splunk immediately. I recommend this approach.The main difference being that you'll need to setup a TCP Input in Splunk first.

preben12
Communicator

Hi Damien

Good to know. I'll use TCPInput or rest for real time scenarios.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...