You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: README.md
+8-1Lines changed: 8 additions & 1 deletion
Original file line number
Diff line number
Diff line change
@@ -174,7 +174,7 @@ Use the below schema to configure Splunk Connect for Kafka
174
174
|`splunk.hec.json.event.formatted`| Set to `true` for events that are already in HEC format. Valid settings are `true` or `false`. |`false`|
175
175
|`splunk.hec.max.outstanding.events`| Maximum amount of un-acknowledged events kept in memory by connector. Will trigger back-pressure event to slow down collection if reached. |`1000000`|
176
176
|`splunk.hec.max.retries`| Amount of times a failed batch will attempt to resend before dropping events completely. Warning: This will result in data loss, default is `-1` which will retry indefinitely |`-1`|
177
-
|`splunk.hec.backoff.threshhold.seconds`| The amount of time Splunk Connect for Kafka waits to attempt resending after errors from a HEC endpoint." |`60`|
177
+
|`splunk.hec.backoff.threshhold.seconds`| The amount of duration the Indexer object will be stopped after getting error code while posting the data.</br> **NOTE:** <br/> Other Indexer won't get affected." |`60`|
178
178
|`splunk.hec.lb.poll.interval`| Specify this parameter(in seconds) to control the polling interval(increase to do less polling, decrease to do more frequent polling, set `-1` to disable polling) |`120`|
179
179
|`splunk.hec.enable.compression`| Valid settings are true or false. Used for enable or disable gzip-compression. |`false`|
180
180
### Acknowledgement Parameters
@@ -233,6 +233,13 @@ Use the below schema to configure Splunk Connect for Kafka
233
233
|`timestamp.regex`| Regex for timestamp extraction. <br/> **NOTE:** <br/> Regex must have name captured group `"time"` For eg.: `\\\"time\\\":\\s*\\\"(?<time>.*?)\"`|`""`|
234
234
|`timestamp.format`| Time-format for timestamp extraction .<br/>For eg.: <br/>If timestamp is `1555209605000` , set `timestamp.format` to `"epoch"` format .<br/> If timestamp is `Jun 13 2010 23:11:52.454 UTC` , set `timestamp.format` to `"MMM dd yyyy HH:mm:ss.SSS zzz"`|`""`|
235
235
236
+
### Out-of-band Health Checks and In-band Health Checks
237
+
| Health Checks | Description |
238
+
|-------- |----------------------------|
239
+
|`Out of band health check`| This health check targets Loadbalancer and aims to remove all the unhealthy channels from the pool; all unhealthy channels are released for the configurable period using the parameter `splunk.hec.lb.poll.interval`, Although this is configurable (by default 120 seconds), It may still get a 503 result code from the Splunk indexer. For that, there is another health check, and it can be called the in-band-health check. |
240
+
|`In band healthcheck`| This health check targets Indexer object while posting data. If an error code is received, then it will trigger this health check. When this check fails, It will Pause the indexing from the Particular Indexer object for a configurable time using the parameter `Splunk.hec.backoff.threshhold.seconds` and trigger backpressure handling So that event that could not be indexed will be retried again. |
241
+
242
+
236
243
## Load balancing
237
244
238
245
See [Splunk Docs](https://docs.splunk.com/Documentation/KafkaConnect/latest/User/LoadBalancing) for considerations when using load balancing in your deployment.
0 commit comments