Splunk Enterprise

"Universal Forwarder" How to send

oda
Communicator

Is the Universal Forwarder sending one line at a time?
Is there such a setting?
Is there sending multiple lines at once?

I read the manual but I could not find the description.

And,
When sending line by line
How do you judge a party?

Tags (1)
0 Karma
1 Solution

bheemireddi
Communicator

Hi oda,

Below link might help you understand how the data being send from the forwarder to the indexer. Forwarder basically sends in approximately 64KB blocks. There are few settings in outputs.conf/props.conf might help understand how the flow works between forwarder and indexer depending on the version of Splunk you are running

Explore these options: outputs.conf
forceTimebasedAutoLB
autoLBFrequency

Props.conf (in the latest versions of Splunk)
EVENT_BREAKER_ENABLE and
EVENT_BREAKER

.conf.spec files should give you enough description of the settings.

https://docs.splunk.com/Documentation/Forwarder/6.6.2/Forwarder/Protectagainstthelossofin-flightdata

View solution in original post

0 Karma

bheemireddi
Communicator

Hi oda,

Below link might help you understand how the data being send from the forwarder to the indexer. Forwarder basically sends in approximately 64KB blocks. There are few settings in outputs.conf/props.conf might help understand how the flow works between forwarder and indexer depending on the version of Splunk you are running

Explore these options: outputs.conf
forceTimebasedAutoLB
autoLBFrequency

Props.conf (in the latest versions of Splunk)
EVENT_BREAKER_ENABLE and
EVENT_BREAKER

.conf.spec files should give you enough description of the settings.

https://docs.splunk.com/Documentation/Forwarder/6.6.2/Forwarder/Protectagainstthelossofin-flightdata

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...