Splunk Enterprise

"Universal Forwarder" How to send

oda
Communicator

Is the Universal Forwarder sending one line at a time?
Is there such a setting?
Is there sending multiple lines at once?

I read the manual but I could not find the description.

And,
When sending line by line
How do you judge a party?

Tags (1)
0 Karma
1 Solution

bheemireddi
Communicator

Hi oda,

Below link might help you understand how the data being send from the forwarder to the indexer. Forwarder basically sends in approximately 64KB blocks. There are few settings in outputs.conf/props.conf might help understand how the flow works between forwarder and indexer depending on the version of Splunk you are running

Explore these options: outputs.conf
forceTimebasedAutoLB
autoLBFrequency

Props.conf (in the latest versions of Splunk)
EVENT_BREAKER_ENABLE and
EVENT_BREAKER

.conf.spec files should give you enough description of the settings.

https://docs.splunk.com/Documentation/Forwarder/6.6.2/Forwarder/Protectagainstthelossofin-flightdata

View solution in original post

0 Karma

bheemireddi
Communicator

Hi oda,

Below link might help you understand how the data being send from the forwarder to the indexer. Forwarder basically sends in approximately 64KB blocks. There are few settings in outputs.conf/props.conf might help understand how the flow works between forwarder and indexer depending on the version of Splunk you are running

Explore these options: outputs.conf
forceTimebasedAutoLB
autoLBFrequency

Props.conf (in the latest versions of Splunk)
EVENT_BREAKER_ENABLE and
EVENT_BREAKER

.conf.spec files should give you enough description of the settings.

https://docs.splunk.com/Documentation/Forwarder/6.6.2/Forwarder/Protectagainstthelossofin-flightdata

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...