Hi,
I am currently trying to read logs file of size 10Gb. I have changed thruput to 0 but still takes about 30 min-1 hr for Splunk to finish reading the file. Is there a way to increase the reading speed further for splunk UF.
Can you show us your props.conf
and inputs.conf
stanza? Have you tried to set EVENT_BREAKER
as well as EVENT_BREAKER_ENABLE
in the props.conf for that sourcetype? I don't know of any performance tests done using those settings, but I'd try setting
EVENT_BREAKER_ENABLE = true
EVENT_BREAKER = \r\n
Skalli