Splunk Enterprise

How will the data accumulate in the persistent queue of the universal forwarder?

human96
Communicator
i have 1 universal forwarder and 2 heavy forwarder.
If two of my heavy forwarder lost communication with the UF at the same time, how will the data accumulate in the persistent queue of the UF? 
 
please provide splunk documentation or previous splunk community Q&A if you have any.
 
0 Karma

human96
Communicator

i installed  a universal forwarder in Windows server 2019.
assume i configured for 2 heavy forwarder and persistent queue is 10 GB. Does that mean i'll get 20 GB for 2 heavy forwarder or 10 GB for 2 forwarder ?
where and how can i check my persistent queue, whether the data is storing or not ?  

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @human96 

Just one thing to highlight
Persistent queuies are not avaiable to all inputs ex: file monitoring , 

it only works with follwing inputs 

SanjayReddy_0-1646662589868.png

and regarding your question for queue size  

it would be 10 GB for all, it doesnt depend on forwarder count 

Persistent queuies location 

SanjayReddy_2-1646662824495.png

 

SanjayReddy
SplunkTrust
SplunkTrust

Hi @human96 

data accumulate in the persistent queue based on size you defined for  it inputs.conf

SanjayReddy_1-1646652480211.png

https://docs.splunk.com/Documentation/Splunk/latest/Data/Usepersistentqueues

 

 

Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...