Splunk Search

SPL to identify UFs needed to increase pipeline sets

jaracan
Communicator

Hi All,

We are planning to configure some of our universal forwarders to use multiple pipeline sets. Do you have some sort of SPL that we can use to identify which forwarders have blocking queues and needs to increase the number of pipeline set.

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

When a queue is blocked it's usually because something downstream is unable to keep up with things.  Often that's either the network or the indexers.  In those cases, adding another pipeline to the UF will just make things worse.

Use the Monitoring Console to check the health of the indexers.  Treat what you find.

Increasing the maxKBps setting in the UF's limits.conf file may get things moving.

To see numbers, this query may help:

index=_internal component=Metrics group=queue
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...