Splunk Enterprise

How will the data accumulate in the persistent queue of the universal forwarder?

human96
Communicator
i have 1 universal forwarder and 2 heavy forwarder.
If two of my heavy forwarder lost communication with the UF at the same time, how will the data accumulate in the persistent queue of the UF? 
 
please provide splunk documentation or previous splunk community Q&A if you have any.
 
0 Karma

human96
Communicator

i installed  a universal forwarder in Windows server 2019.
assume i configured for 2 heavy forwarder and persistent queue is 10 GB. Does that mean i'll get 20 GB for 2 heavy forwarder or 10 GB for 2 forwarder ?
where and how can i check my persistent queue, whether the data is storing or not ?  

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @human96 

Just one thing to highlight
Persistent queuies are not avaiable to all inputs ex: file monitoring , 

it only works with follwing inputs 

SanjayReddy_0-1646662589868.png

and regarding your question for queue size  

it would be 10 GB for all, it doesnt depend on forwarder count 

Persistent queuies location 

SanjayReddy_2-1646662824495.png

 

SanjayReddy
SplunkTrust
SplunkTrust

Hi @human96 

data accumulate in the persistent queue based on size you defined for  it inputs.conf

SanjayReddy_1-1646652480211.png

https://docs.splunk.com/Documentation/Splunk/latest/Data/Usepersistentqueues

 

 

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...