I am trying to ingest data into Splunk via Splunk HEC using a python script. I am also sending the data in batches.
What should be the optimum size of the payload(data) that can be sent in a single post request to optimize the performance of the ingestion script?
There is a Splunk conf presentation that covers this but I'm unsure which one. It will be on https://conf.splunk.com/watch/conf-online.html