Splunk Enterprise

How will the data accumulate in the persistent queue of the universal forwarder?

human96
Communicator
i have 1 universal forwarder and 2 heavy forwarder.
If two of my heavy forwarder lost communication with the UF at the same time, how will the data accumulate in the persistent queue of the UF? 
 
please provide splunk documentation or previous splunk community Q&A if you have any.
 
0 Karma

human96
Communicator

i installed  a universal forwarder in Windows server 2019.
assume i configured for 2 heavy forwarder and persistent queue is 10 GB. Does that mean i'll get 20 GB for 2 heavy forwarder or 10 GB for 2 forwarder ?
where and how can i check my persistent queue, whether the data is storing or not ?  

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @human96 

Just one thing to highlight
Persistent queuies are not avaiable to all inputs ex: file monitoring , 

it only works with follwing inputs 

SanjayReddy_0-1646662589868.png

and regarding your question for queue size  

it would be 10 GB for all, it doesnt depend on forwarder count 

Persistent queuies location 

SanjayReddy_2-1646662824495.png

 

SanjayReddy
SplunkTrust
SplunkTrust

Hi @human96 

data accumulate in the persistent queue based on size you defined for  it inputs.conf

SanjayReddy_1-1646652480211.png

https://docs.splunk.com/Documentation/Splunk/latest/Data/Usepersistentqueues

 

 

Get Updates on the Splunk Community!

Splunk Answers Content Calendar, July Edition I

Welcome to another month of Community Content Calendar series! For the month of July, we will be focusing on ...

Secure Your Future: Mastering Upgrade Readiness for Splunk 10

Spotlight: The Splunk Health Assistant Add-On  The Splunk Health Assistant Add-On is your ultimate companion ...

Observability Unlocked: Kubernetes & Cloud Monitoring with Splunk IM

Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team on ...