Splunk Search

SPL to identify UFs needed to increase pipeline sets

jaracan
Communicator

Hi All,

We are planning to configure some of our universal forwarders to use multiple pipeline sets. Do you have some sort of SPL that we can use to identify which forwarders have blocking queues and needs to increase the number of pipeline set.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

When a queue is blocked it's usually because something downstream is unable to keep up with things.  Often that's either the network or the indexers.  In those cases, adding another pipeline to the UF will just make things worse.

Use the Monitoring Console to check the health of the indexers.  Treat what you find.

Increasing the maxKBps setting in the UF's limits.conf file may get things moving.

To see numbers, this query may help:

index=_internal component=Metrics group=queue
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...