Splunk Search

Help how to increase splunk forwarder capacity?

dhavamanis
Builder

there's a backlog of over 350,000,000 records and we are generating over 20,000,000 records per day just from this source. we need to increase the forwarding capacity in Splunk forwarder. can you please provide the configuration to increase the Splunk forwarding speed.

0 Karma
1 Solution

aholzer
Motivator

What error are you seeing in your $SPLUNK_HOME/var/log/splunk/splunkd.log?

If it is that your maxKBps has been reached and therefore it is throttling the amount of data being sent, then you can update "maxKBps" in your limits.conf:

[thruput]
#default for maxKBps is 256. If this is your problem, you may want to increase it
maxKBps = 256

Be careful increasing this number, as you may simply move the bottle neck to your indexers, if they don't have the capacity to handle that amount of data.

View solution in original post

aholzer
Motivator

What error are you seeing in your $SPLUNK_HOME/var/log/splunk/splunkd.log?

If it is that your maxKBps has been reached and therefore it is throttling the amount of data being sent, then you can update "maxKBps" in your limits.conf:

[thruput]
#default for maxKBps is 256. If this is your problem, you may want to increase it
maxKBps = 256

Be careful increasing this number, as you may simply move the bottle neck to your indexers, if they don't have the capacity to handle that amount of data.

Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...