splunk设置realtime search的配置

来源:互联网 发布:中文学位论文数据库 编辑:程序博客网 时间:2024/05/20 13:40

禁用realtime search,可以在indexes.conf和limits.conf里面配置。

indexes.conf

[default]

enableRealtimeSearch= <bool>

 

 

limits.conf

[search]

max_rt_search_multiplier= <decimal number>

realtime_buffer =<int>

max_rt_search_multiplier



设置realtime search,可以在limits.conf里配置。

limits.conf

[realtime]

queue_size =<int>

blocking = [0|1]

max_blocking_secs =<int>

indexfilter = [0|1]

queue_size =<int>

The size of queue foreach real-time search. Must be > 0.

Defaults to 10000.

blocking =[0|1]

Specifies whether theindexer should block if a queue is full.

Defaults to false(0).

max_blocking_secs =<int>

The maximum time toblock if the queue is full. This option is meaningless, if blocking = false.

Means "nolimit" if set to 0.

Defaults to 60.

indexfilter = [0|1]

Specifies whether theindexer should pre-filter events for efficiency.

Defaults to true (1).


原创粉丝点击