All Apps and Add-ons

How to find the delay/latency factor induced by Splunk?

bkumarm
Contributor

We have a setup where the logs are generated continuously and are being forwarded into Splunk indexers and also into another external application.
Earlier, the application was directly reading from the server with minimal delay.
After we introduced Splunk, we are observing delay of about 13 to 19 secs.
The maximum approved delay factor is 5 secs.
How do I find out where is the delay being induced?
I have _time which is the event occurrence time, _indextime which gives indexed time. Using Splunk App for Stream, I am able to get timestamp factor too.
However, I am struggling to get the logic of where the delay is.
Basically, if I can get the time of arrival of log into Splunk, I can calculate the difference between index time and arrival time.

How do I get the arrival time into Splunk?
Any ideas? Any one faced such situation?

0 Karma
1 Solution

vshcherbakov_sp
Splunk Employee
Splunk Employee

Hello,

You can get the time of arrival into splunk (i.e. the event's index time) via the _indextime field.

View solution in original post

0 Karma

vshcherbakov_sp
Splunk Employee
Splunk Employee

Hello,

You can get the time of arrival into splunk (i.e. the event's index time) via the _indextime field.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...