Getting Data In

Impact of LineBreakingProcessor and AggregateMiningProcessor on indexing performance

swatishs
Explorer

When indexing a directory containing html files, log files, zipped log files and gzipped log files, I am getting many LineBreakingProcessor and AggregateMiningProcessor warnings. It is scattered with them.
LineBreakingProcessor: When a line exceepds a predefined lenght (default 10,000bytes)
AggregateMiningProcessor: When an event has more than 256 lines.

Can someone please elaborate more on the performance impact of these?

0 Karma
Get Updates on the Splunk Community!

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...