Splunk Enterprise

How will the data accumulate in the persistent queue of the universal forwarder?

human96
Communicator
i have 1 universal forwarder and 2 heavy forwarder.
If two of my heavy forwarder lost communication with the UF at the same time, how will the data accumulate in the persistent queue of the UF? 
 
please provide splunk documentation or previous splunk community Q&A if you have any.
 
0 Karma

human96
Communicator

i installed  a universal forwarder in Windows server 2019.
assume i configured for 2 heavy forwarder and persistent queue is 10 GB. Does that mean i'll get 20 GB for 2 heavy forwarder or 10 GB for 2 forwarder ?
where and how can i check my persistent queue, whether the data is storing or not ?  

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @human96 

Just one thing to highlight
Persistent queuies are not avaiable to all inputs ex: file monitoring , 

it only works with follwing inputs 

SanjayReddy_0-1646662589868.png

and regarding your question for queue size  

it would be 10 GB for all, it doesnt depend on forwarder count 

Persistent queuies location 

SanjayReddy_2-1646662824495.png

 

SanjayReddy
SplunkTrust
SplunkTrust

Hi @human96 

data accumulate in the persistent queue based on size you defined for  it inputs.conf

SanjayReddy_1-1646652480211.png

https://docs.splunk.com/Documentation/Splunk/latest/Data/Usepersistentqueues

 

 

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...