Getting Data In

How to schedule a transfer on a forwarder?


I create a forwarder on a remote site. The speed of network is limited. I need transfer the event log in middle-night on the forwarder.

How can I configure the transfer start at middle-night, pause at six o'clock?

Thank you in advance.

Tags (1)
0 Karma

Splunk Employee
Splunk Employee

Create a batch script that reduce the thruput during day time, and unleash the beast at night.
I assume that you are on windows
create %SPLUNK\_HOME%\etc\system\local\limits.conf_superslow

# default was 256

and create %SPLUNK\_HOME%\etc\system\local\limits.conf_superfast

# for unlimited

Then at night time run a batch using the windows scheduler (running under the correct user of course)

cp %SPLUNK_HOME%\etc\system\local\limits.conf_superfast %SPLUNK_HOME%\etc\system\local\limits.conf
%SPLUNK\_HOME%\bin\splunk restart

and in the morning

cp %SPLUNK_HOME%\etc\system\local\limits.conf_superslow %SPLUNK_HOME%\etc\system\local\limits.conf
%SPLUNK_HOME%\bin\splunk restart

0 Karma


@shizl, There are couple of ways to accomplish what your want or least come close, scripted input or oneshot. Please read my previous post. Hope this helps.

If your network is limited you may also want to enable indexer achnowledgement to prevent data lost in-flight.

Protect against loss of in-flight data

Answers: Can you set a certain time forwarding occurs


collect and transfer cannot be scheduled then you will need to use a local cron job to stop & start splunk.


What do you mean? Configure what?

0 Karma


How to configure the forwarder or indexer without stop splunk?

0 Karma


How to configure the forwarder or indexer without stop splunk?

0 Karma
Get Updates on the Splunk Community!

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...

What's New in Splunk Cloud Platform 9.0.2208?!

Howdy!  We are happy to share the newest updates in Splunk Cloud Platform 9.0.2208! Analysts can benefit ...

Admin Console: A Single, Unified Interface for All Your Cloud Admin Needs

WATCH NOWJoin us to learn how the admin console can save you time and give you more control over the Splunk® ...