Which network input option provides durable file-system buffering of data to mitigate data loss due to network outages and splunkd restarts?
Which network input option provides durable file-system buffering of data to mitigate data loss due to network outages and splunkd restarts?
The 'persistentQueueSize' option in Splunk provides durable file-system buffering of data. This buffering helps to mitigate data loss that could occur due to network outages and restarts of the splunkd process. By using persistent queues, data that is read from network inputs can be temporarily stored on disk, ensuring that the data is not lost if the network connection to the indexers is interrupted or if the Spunk instance is restarted.
Splunk data admin slides page 145 CLEARLY shows that Persistent queue provides additional file-system buffering of data and useful for high volume data and in the case of network outage to indexers.
https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/Usepersistentqueues