Splunk Search

SPL to identify UFs needed to increase pipeline sets

jaracan
Communicator

Hi All,

We are planning to configure some of our universal forwarders to use multiple pipeline sets. Do you have some sort of SPL that we can use to identify which forwarders have blocking queues and needs to increase the number of pipeline set.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

When a queue is blocked it's usually because something downstream is unable to keep up with things.  Often that's either the network or the indexers.  In those cases, adding another pipeline to the UF will just make things worse.

Use the Monitoring Console to check the health of the indexers.  Treat what you find.

Increasing the maxKBps setting in the UF's limits.conf file may get things moving.

To see numbers, this query may help:

index=_internal component=Metrics group=queue
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...