Splunk Search

SPL to identify UFs needed to increase pipeline sets

jaracan
Communicator

Hi All,

We are planning to configure some of our universal forwarders to use multiple pipeline sets. Do you have some sort of SPL that we can use to identify which forwarders have blocking queues and needs to increase the number of pipeline set.

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

When a queue is blocked it's usually because something downstream is unable to keep up with things.  Often that's either the network or the indexers.  In those cases, adding another pipeline to the UF will just make things worse.

Use the Monitoring Console to check the health of the indexers.  Treat what you find.

Increasing the maxKBps setting in the UF's limits.conf file may get things moving.

To see numbers, this query may help:

index=_internal component=Metrics group=queue
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...