Splunk Search

Index bz2 files take too much time

indeed_2000
Motivator

Hi

I have a directory that contain 60 bz2 files. Totally 27 GB

After 24 hours still index processing not completed!

How can I check index status of this directory? (How much remain? How much pass?)

How can I tune splunk to index compress files more quickly?

FYI: there is no issue about license limitation.

FYI: I have enough disk space.

 

any idea?

Thanks

Labels (2)
Tags (2)
0 Karma
1 Solution

venkatasri
SplunkTrust
SplunkTrust

@indeed_2000 

The thruput is limited to 256 Kbps in limit.conf on UF,  it depends on network speed you have to calculate how much data can be ingested.

Issue following command under $SPLUNK_HOME/bin and when prompt provide the username/password. This will provide the list of the files being read by UF and their current stage/progress.

./splunk list inputstatus

 

----

An upvote would be appreciated and Accept solution if it helps!

View solution in original post

codebuilder
Influencer

To ingest these files Splunk first has to decompress them and that is a single threaded process (and consumes a lot of memory).

You'll see better performance by ingesting them before they are compressed, or decompress them prior to ingestion.

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

venkatasri
SplunkTrust
SplunkTrust

@indeed_2000 

The thruput is limited to 256 Kbps in limit.conf on UF,  it depends on network speed you have to calculate how much data can be ingested.

Issue following command under $SPLUNK_HOME/bin and when prompt provide the username/password. This will provide the list of the files being read by UF and their current stage/progress.

./splunk list inputstatus

 

----

An upvote would be appreciated and Accept solution if it helps!

Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...