Splunk Enterprise

"Universal Forwarder" How to send

oda
Communicator

Is the Universal Forwarder sending one line at a time?
Is there such a setting?
Is there sending multiple lines at once?

I read the manual but I could not find the description.

And,
When sending line by line
How do you judge a party?

Tags (1)
0 Karma
1 Solution

bheemireddi
Communicator

Hi oda,

Below link might help you understand how the data being send from the forwarder to the indexer. Forwarder basically sends in approximately 64KB blocks. There are few settings in outputs.conf/props.conf might help understand how the flow works between forwarder and indexer depending on the version of Splunk you are running

Explore these options: outputs.conf
forceTimebasedAutoLB
autoLBFrequency

Props.conf (in the latest versions of Splunk)
EVENT_BREAKER_ENABLE and
EVENT_BREAKER

.conf.spec files should give you enough description of the settings.

https://docs.splunk.com/Documentation/Forwarder/6.6.2/Forwarder/Protectagainstthelossofin-flightdata

View solution in original post

0 Karma

bheemireddi
Communicator

Hi oda,

Below link might help you understand how the data being send from the forwarder to the indexer. Forwarder basically sends in approximately 64KB blocks. There are few settings in outputs.conf/props.conf might help understand how the flow works between forwarder and indexer depending on the version of Splunk you are running

Explore these options: outputs.conf
forceTimebasedAutoLB
autoLBFrequency

Props.conf (in the latest versions of Splunk)
EVENT_BREAKER_ENABLE and
EVENT_BREAKER

.conf.spec files should give you enough description of the settings.

https://docs.splunk.com/Documentation/Forwarder/6.6.2/Forwarder/Protectagainstthelossofin-flightdata

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...