今天碰到的case, 发现splunk forwarder 数据没有全部发送到indexer 上,查找原因,是这两个参数的问题:max_fd 和 maxKBps
1: 查找log:
2-14-2022 18:46:04.142 -0800 INFO ThruputProcessor - Current data throughput (274 kb/s) has reached maxKBps. As a result, data forwarding may be throttled. Consider increasing the value of maxKBps in limits.conf.
2: 查找splunk 的maxKBps 的设置:
And the bandwidth is limited at 256/s as it's default value for universal forwarder:
$SPLUNK_HOME/etc/apps/SplunkUniversalForwarder/default/limits.conf:
# Version 8.1.4
[thruput]
maxKBps = 256
3: 解决方法:
增加下面文件