Getting Data In

Forwarder capacity?

msarro
Builder

I noticed that in the capacity planning guide, there is no mention of the capacity of a forwarder. Right now I am looking at sending a significant amount of data to two different forwarders. How much data can the forwarder handle? These are heavy forwarders, I know the guideline for an indexer is 100GB/day, but I can't find anything similar for forwarders.

Tags (1)
0 Karma

kristian_kolb
Ultra Champion

First: How much is a significant amount?

I think that a lot of this depends on how you set up the forwarding. If you monitor a directory containing thousands of files, with new files being added constantly you may run into problems just because the forwarder will have to keep track of so many files. I've seen forwarders (UF on windows) going up to 35-40% CPU usage for this reason alone (the actual log amount was less than a 100MB daily).

If you have a relatively 'clean' source of logs, i.e. just a few files you could probably send out quite a large amount. The UF is capped at 256KBps, although this can be changed, so in theory this means that a single forwarder can send 21GB/day by default.

hope this helps,

Kristian

Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...