Splunk Search

Splunk Listen Backlog Queue

chrisgoffient
New Member

I have a client that is using Splunk enterprise using TCP, we've been monitoring the number of ListenOverflows, and increased net.core.somaxconn from the original 128. We noticed after a splunk restart, it looks like listen(...) is still setting 128. Is there a tunable in Splunk for TCP over 9997? I couldn't find it in the documentation. Most systems allow this to be tunable (i.e nginx, apache, etc).

Tags (2)
0 Karma

mwidjaja_splunk
Splunk Employee
Splunk Employee

To make that change, you'll need to edit $SPLUNK_HOME/etc/splunk-launch.conf and add this line below
SPLUNK_LISTEN_BACKLOG=new setting

And restart

0 Karma
Get Updates on the Splunk Community!

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

What's New in Splunk Observability Cloud and Splunk AppDynamics - May 2025

This month, we’re delivering several new innovations in Splunk Observability Cloud and Splunk AppDynamics ...

Getting Started with Splunk Artificial Intelligence, Insights for Nonprofits, and ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...