Dear Splunkers,
I have two forwarders running in my Splunk setup and they are transferring data at a rate of 256 KBPS, which is as per the transfer rate setup in LIMITS.conf.
However this is not serving my purpose, as I can see a delay in the logs being indexed (at least 4 -5 hours). Could you please advice if you have encountered similar issue and what solution could probably fix it,
i did some research of my own from past few days and found that by abruptly increasing the maxKBps = 0 or maxKBps = xxxx, it might result in blocked queues in indexer and forwarder too. Any idea how to get around this ? Will really appreciate any pointer to solve this issue.
thanks in advance!
Thanks,
Seema
... View more