Hi. I also have a large size files on some servers, about 10Gb per day in 3 files each server, and those files during the day are very delayed to be ingested, with ACK to true. While those files delay from 1 to also 4 hours to be indexed, other files on same servers are ingested fine in realtime. So, also with UF 8.2.12, i think it's a thruput of Network Infrastructure, or maybe too many datas from those inputs 🤷♂️ I also have [thruput]
maxKBps = 0
[general]
parallelIngestionPipelines = 2
[queue]
maxSize = 100MB
[queue=parsingQueue]
maxSize = 10MB I don't think there are other methods, since it's a phisiological problem 🤷♂️ The only way, maybe, is to add more Indexers in SPLUNK Infra or ask the Applicative Teams to split those file in more servers 🤷♂️
... View more