Greetz,
When using the SoS app along with forwarded _internal indexes from heavy forwarders I get no results under S.o.S - Splunk on Splunk > Indexing Performance for "Estimated indexing rate" and "Fill ratio of data processing queues".
Upon inspecting the search I see we get no "group=per_sourcetype_thruput" in the metrics.log.
This metric is however on our indexers but then that's not the thruput we want to see.
We are "indexing" in memory on our heavy forwarders in order to save bandwidth by discarding
events at the collector.
We would like to see if any events are being dropped on the collector or queues blocked etc. Reason being we have several inputs from a 100Mbit LAN into the collector and outputs via 2Mbit WAN link upstream to our three indexers.
Is it possible to get this from SoS in this configuration?
Thank you.