splunk設置realtime search的配置

禁用realtime search,可以在indexes.conf和limits.conf裏面配置。

indexes.conf

[default]

enableRealtimeSearch= <bool>

 

 

limits.conf

[search]

max_rt_search_multiplier= <decimal number>

realtime_buffer =<int>

max_rt_search_multiplier



設置realtime search,可以在limits.conf裏配置。

limits.conf

[realtime]

queue_size =<int>

blocking = [0|1]

max_blocking_secs =<int>

indexfilter = [0|1]

queue_size =<int>

The size of queue foreach real-time search. Must be > 0.

Defaults to 10000.

blocking =[0|1]

Specifies whether theindexer should block if a queue is full.

Defaults to false(0).

max_blocking_secs =<int>

The maximum time toblock if the queue is full. This option is meaningless, if blocking = false.

Means "nolimit" if set to 0.

Defaults to 60.

indexfilter = [0|1]

Specifies whether theindexer should pre-filter events for efficiency.

Defaults to true (1).


發表評論
所有評論
還沒有人評論,想成為第一個評論的人麼? 請在上方評論欄輸入並且點擊發布.
相關文章