Splunk Enterprise

"Universal Forwarder" How to send

oda
Communicator

Is the Universal Forwarder sending one line at a time?
Is there such a setting?
Is there sending multiple lines at once?

I read the manual but I could not find the description.

And,
When sending line by line
How do you judge a party?

Tags (1)
0 Karma
1 Solution

bheemireddi
Communicator

Hi oda,

Below link might help you understand how the data being send from the forwarder to the indexer. Forwarder basically sends in approximately 64KB blocks. There are few settings in outputs.conf/props.conf might help understand how the flow works between forwarder and indexer depending on the version of Splunk you are running

Explore these options: outputs.conf
forceTimebasedAutoLB
autoLBFrequency

Props.conf (in the latest versions of Splunk)
EVENT_BREAKER_ENABLE and
EVENT_BREAKER

.conf.spec files should give you enough description of the settings.

https://docs.splunk.com/Documentation/Forwarder/6.6.2/Forwarder/Protectagainstthelossofin-flightdata

View solution in original post

0 Karma

bheemireddi
Communicator

Hi oda,

Below link might help you understand how the data being send from the forwarder to the indexer. Forwarder basically sends in approximately 64KB blocks. There are few settings in outputs.conf/props.conf might help understand how the flow works between forwarder and indexer depending on the version of Splunk you are running

Explore these options: outputs.conf
forceTimebasedAutoLB
autoLBFrequency

Props.conf (in the latest versions of Splunk)
EVENT_BREAKER_ENABLE and
EVENT_BREAKER

.conf.spec files should give you enough description of the settings.

https://docs.splunk.com/Documentation/Forwarder/6.6.2/Forwarder/Protectagainstthelossofin-flightdata

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...