Splunk Enterprise

"Universal Forwarder" How to send

oda
Communicator

Is the Universal Forwarder sending one line at a time?
Is there such a setting?
Is there sending multiple lines at once?

I read the manual but I could not find the description.

And,
When sending line by line
How do you judge a party?

Tags (1)
0 Karma
1 Solution

bheemireddi
Communicator

Hi oda,

Below link might help you understand how the data being send from the forwarder to the indexer. Forwarder basically sends in approximately 64KB blocks. There are few settings in outputs.conf/props.conf might help understand how the flow works between forwarder and indexer depending on the version of Splunk you are running

Explore these options: outputs.conf
forceTimebasedAutoLB
autoLBFrequency

Props.conf (in the latest versions of Splunk)
EVENT_BREAKER_ENABLE and
EVENT_BREAKER

.conf.spec files should give you enough description of the settings.

https://docs.splunk.com/Documentation/Forwarder/6.6.2/Forwarder/Protectagainstthelossofin-flightdata

View solution in original post

0 Karma

bheemireddi
Communicator

Hi oda,

Below link might help you understand how the data being send from the forwarder to the indexer. Forwarder basically sends in approximately 64KB blocks. There are few settings in outputs.conf/props.conf might help understand how the flow works between forwarder and indexer depending on the version of Splunk you are running

Explore these options: outputs.conf
forceTimebasedAutoLB
autoLBFrequency

Props.conf (in the latest versions of Splunk)
EVENT_BREAKER_ENABLE and
EVENT_BREAKER

.conf.spec files should give you enough description of the settings.

https://docs.splunk.com/Documentation/Forwarder/6.6.2/Forwarder/Protectagainstthelossofin-flightdata

0 Karma
Get Updates on the Splunk Community!

Uncovering Multi-Account Fraud with Splunk Banking Analytics

Last month, I met with a Senior Fraud Analyst at a nationally recognized bank to discuss their recent success ...

Secure Your Future: A Deep Dive into the Compliance and Security Enhancements for the ...

What has been announced?  In the blog, “Preparing your Splunk Environment for OpensSSL3,”we announced the ...

New This Month in Splunk Observability Cloud - Synthetic Monitoring updates, UI ...

This month, we’re delivering several platform, infrastructure, application and digital experience monitoring ...