Splunk Search

Splunk Enterprise Flow data indigestion limits

hariskhan
Explorer

Hi all,

Can some one tell about Network flows indigestion capacity of Splunk enterprise solution.Like how much flows/sec at min and max splunk can accept.

Also any suggestion on receiving flows on separate interface of hardware on which splunk is installed. I mean can a dedicated interface be used on splunk machine to receive network flows?.

Tags (1)
0 Karma

hariskhan
Explorer

Am talking about network flows not network syslogs or any device logs. That isi network moving traffic sessions data

0 Karma

hariskhan
Explorer

any update please?.

0 Karma

hariskhan
Explorer

I know about this doc. But this doc doesn't mention any limits on how much network flows a base machine or mid range can handle before it can overwhelm the link or machine performance.

0 Karma

harsmarvania57
Ultra Champion

Hi,

Have look at https://docs.splunk.com/Documentation/Splunk/7.2.3/Capacity/Referencehardware#Maximum_performance_ca... , which describes that with reference hardware you can ingest how much data but this depends on many more factors like IOPS, Different custom parsing.

0 Karma
Get Updates on the Splunk Community!

Monitoring Postgres with OpenTelemetry

Behind every business-critical application, you’ll find databases. These behind-the-scenes stores power ...

Mastering Synthetic Browser Testing: Pro Tips to Keep Your Web App Running Smoothly

To start, if you're new to synthetic monitoring, I recommend exploring this synthetic monitoring overview. In ...

Splunk Edge Processor | Popular Use Cases to Get Started with Edge Processor

Splunk Edge Processor offers more efficient, flexible data transformation – helping you reduce noise, control ...