Hello Splunkers,
Lately, we have been facing issues in onboarding the data due to the “Could not send…..parsing queue full” issue whenever there is a data burst.
We have been setting maxkbps in limits.conf to unlimited(0) and parsing queue size to 10 MB from 512kb temporarily as a workaround.
What is the splunk recommended best practice to address this issue.
Splunk UF version - 6.4
↧