Getting Data In

What is splunk's capacity for receiving UDP events/second?

Chris_R_
Splunk Employee
Splunk Employee

We have an index that gets around 2million events/hour and it seems not a sizable number of events are not making it from the manager to our splunk instance. At the very least we are talking about 60,000 events in a 24 hours period. This would seem to be beyond the normal expected loss for connectionless UDP. Is it possible splunk is being inundated with so many events that some are being discarded?

Tags (4)
1 Solution

Simeon
Splunk Employee
Splunk Employee

You can examine the performance of Splunk by examining the thruput for that particular input. Using UDP as the network protocol is not recommended if you are concerned about data loss. There is the following wiki topic that details tuning recommendations and some troubleshooting tips:

http://www.splunk.com/wiki/Community:UDPInputs

The capacity of a Splunk instance is mostly determined by the hardware. Our reference architecture (for handling 100 GB/day) is capable of handling peak thruput in excess of 3 MB/sec. I have seen up to 10 MB/sec in some cases.

View solution in original post

Simeon
Splunk Employee
Splunk Employee

You can examine the performance of Splunk by examining the thruput for that particular input. Using UDP as the network protocol is not recommended if you are concerned about data loss. There is the following wiki topic that details tuning recommendations and some troubleshooting tips:

http://www.splunk.com/wiki/Community:UDPInputs

The capacity of a Splunk instance is mostly determined by the hardware. Our reference architecture (for handling 100 GB/day) is capable of handling peak thruput in excess of 3 MB/sec. I have seen up to 10 MB/sec in some cases.

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...