Splunk Enterprise

How will the data accumulate in the persistent queue of the universal forwarder?

human96
Communicator
i have 1 universal forwarder and 2 heavy forwarder.
If two of my heavy forwarder lost communication with the UF at the same time, how will the data accumulate in the persistent queue of the UF? 
 
please provide splunk documentation or previous splunk community Q&A if you have any.
 
0 Karma

human96
Communicator

i installed  a universal forwarder in Windows server 2019.
assume i configured for 2 heavy forwarder and persistent queue is 10 GB. Does that mean i'll get 20 GB for 2 heavy forwarder or 10 GB for 2 forwarder ?
where and how can i check my persistent queue, whether the data is storing or not ?  

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @human96 

Just one thing to highlight
Persistent queuies are not avaiable to all inputs ex: file monitoring , 

it only works with follwing inputs 

SanjayReddy_0-1646662589868.png

and regarding your question for queue size  

it would be 10 GB for all, it doesnt depend on forwarder count 

Persistent queuies location 

SanjayReddy_2-1646662824495.png

 

SanjayReddy
SplunkTrust
SplunkTrust

Hi @human96 

data accumulate in the persistent queue based on size you defined for  it inputs.conf

SanjayReddy_1-1646652480211.png

https://docs.splunk.com/Documentation/Splunk/latest/Data/Usepersistentqueues

 

 

Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...