Hi Friends,
I want to know 2 things as mentioned below:
Thank you Emily
Can you talk more about your services? Im interesting in this.
As usually that depends on what you have on those UF / HFs. How many logs, what are volumes of events and in HF have you running also some other inputs like DBX etc.
You should use your normal monitoring tools to see what happenings on UFs. With HF you could also use MC (monitoring console) and add those HF's as indexer to it. Then just create own custom group for those and separate for real indexers and then you could follow up those with MC. After that you could also see some other splunk's internal metrics like HEC statistic, some queues, pipelines etc. on those.
There is also on request in https://ideas.splunk.com/ideas/EID-I-88 to get own role for HF on MC.
r. Ismo
1 What is the typical CPU & Memory consumption of Splunk Forwarder?
- It really varies based on what you monitor. Monitoring databases, hadoop, etc, can be taxing...
2 Can we set the limit on CPU & Memory utilization by Splunk Forwarder?
- Unfortunately, Splunk lacks hadoop like queues and features to constrain resources.
hello there,
hope it helps