I have an issue with a HF, I'm getting some spikes reaching the 100% when sending data to Splunk Cloud. This happens every 30 seconds approx.
I think this is because of the amount of data we are sending, this is also causing that all data get with a delay to Splunk Cloud, I mean the _time and indextime is different in all data because of this.
So I have some questions:
1- How can I check if I'm sending a big amount of data at similar times during the day? Do you have a query I can use or a dashboard?
2- What are your recommendation to distribute the big data to be sent at different times?
I really appreciate your help on this. Thanks in advance!