Getting Data In

Performance Tuning Suggestions for TCP Syslog Running on Server 2012

jodros
Builder

I know this is not a Splunk specific question, however I have asked a similar question in the past about tuning for UDP syslog on linux. I need to know what to watch out for when dealing with high volumes and bursts of TCP syslog. This is a Server 2012 VM using vmxnet3 drivers. I have maxed out the Small/Large RX Buffers as well as RX Ring #1/#2 Size. I have also tested enabling/disabling LSO V2 (IPv4) but that had little impact.

Any assistance would be appreciated.

Thanks

0 Karma
1 Solution

jodros
Builder

Resolved issue with our RHEL UDP syslog environment. WinOS was not able to increase receive buffers to amount that was required.

View solution in original post

0 Karma

jodros
Builder

Resolved issue with our RHEL UDP syslog environment. WinOS was not able to increase receive buffers to amount that was required.

0 Karma
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...