Quantcast
Channel: Questions in topic: "universal-forwarder"
Viewing all articles
Browse latest Browse all 1551

Are there any specific settings to apply for DC's that generate a lot of logging?

$
0
0
Hello, I'm missing some logging in Splunk from several DC's. Most likely, the reason behind is that the DC's are generating too much logging the Universal Forwarder (UF) is capable of handling. Setting the UF limit uncapped did not solve the issue. What I'm about to try next is to set useACK at the client site. However I still have some questions. Can we enable useACK on the same TCP port (default 9997) which is used for non-ACK traffic? Are there any specific settings which we should apply for DC's generating a lot of logging? Many Thanks. Kind regards, Stefan

Viewing all articles
Browse latest Browse all 1551

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>