...eports: StatsBuffer::read: Row is too large for StatsBuffer, resizing buffer. row_size=77060 needed_space=11536 free_space=153653063 This is soon followed by lots of ~min-by-min output of: S...
...rom Powershell and Perfmon).
My question is: is it possible to have separate buffers on 2 different tcpout groups? So that the filling of one, doesn't affect the other. Failing this, I expect it'll b...
...plunk to use round robin buffers for all data coming in ( syslogs and Sourcefire eStreamer data). E.g. store only data for 30 days and overwrite old data if buffersize is reached. Is there an option t...
...ours. Some data was lost, some was not.
We have PLENTY of disk space on Heavy Forwarders and our understanding was the HF would buffer/cache until the indexers came online. This does not seem to b...
Hello, can you please tell me what happens to email alerts if the smtp used for email delivery is temporary offline? Is there a buffer where alerts are saved and then are sent once the smtp s...
Hi! I have a setup where I must clone and forward data to a third party. Can somebody clarify if I disable useACK that even though a destination is unreachable that the flow to other outputs does n...
...ctivate a config change will usually cause data loss for a period of 1-2 minutes for some of the sources, which is something I would rather avoid. It should be doable by stopping the UFs f...
...ake the search results from the buffer and then searches on it when piping is done.
To clarify if I search for host="some_host" | source="testing_source" does splunk first search for some host and t...
Hello, In a distributed environment with Universal Forwarder, Heavy Forwarder and Indexers, like this one: UF --> HF --> IDX How do you set useACK=true in outputs.conf ? Is it needed t...
...eceiver if current
indexer/receiver is slow.
* A non-zero value means that max send buffer size is set.
* 0 means no limit on max send buffer size.
* Default: 0 Additionally 9.1.3/9.2.1 and above will c...