Splunk Cloud Platform

Use Edge Processors

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

Configure global Edge Processor settings

The Edge Processor service supports several configuration settings that apply to all Edge Processors that are part of the same cloud tenant. These settings determine behavior such as which port your Edge Processors uses to listen for incoming data, and the amount of computing resources that an Edge Processor can use before warnings are raised.

  1. Select Edge Processors, and then select Global settings.
  2. To specify the amount of computing resources that an Edge Processor can use before it enters a Warning state due to high resource usage, select the Other settings tab then select Edit to configure the following settings in the Warning threshold section:
    Field Description
    CPU threshold The percentage of the total allocated CPU processing power that an Edge Processor can use before a warning is raised
    Memory threshold The percentage of the total allocated memory that an Edge Processor can use before a warning is raised
  3. To specify how Edge Processors receive data from universal and heavy forwarders, select Edit in the Splunk forwarders section and then configure the following settings:
    Field Description
    Port The number of the TCP port used to receive data from forwarders
    Maximum channels The number of channels an Edge Processor can use to receive data from forwarders
  4. To specify the port that Edge Processors use to receive data from HTTP clients and logging agents through HTTP Event Collector (HEC), in the HTTP Event Collector section, select Edit then enter your desired port number in the Port field.
  5. To specify the port that Edge Processors use to receive data from syslog data sources, in the Syslog section, select New Port and then configure the following settings:
    Field Description
    Port The number of the TCP or UDP port used to receive data from forwarders
    Source type The metadata assigned to incoming syslog data to allow pipeline processing
    RFC protocol The standard that defines the format of your syslog data
  6. Select Save to save your changes, and then select Edge Processors to return to the Edge Processor management page.
  7. Your updated settings are automatically applied to all current Edge Processors. Additionally, your updated settings are used by default for any new Edge Processors that you set up afterwards.

  8. If you changed the Port setting in the Splunk forwarders or HTTP Event Collector sections, make sure to update the configurations of your data sources to account for the updated port number. Review and update these configurations as needed:
    Type of data source Configuration instructions
    Splunk forwarders In the outputs.conf file, make sure that the server property specifies the correct port number.
    HTTP clients or logging agents using HTTP Event Collector (HEC) Make sure that the HTTP requests for sending data to the Edge Processor are directed to the correct port number.


    If your HTTP requests are directed to a load balancer, make sure that the load balancer is configured to pass the requests to the correct port number.

    Syslog devices Make sure that the syslog requests for sending data to the Edge Processor are directed to the correct port number.
Last modified on 18 September, 2023
PREVIOUS
Manage and uninstall Edge Processors
  NEXT
Edge Processor pipeline syntax

This documentation applies to the following versions of Splunk Cloud Platform: 9.0.2209, 9.0.2303, 9.0.2305, 9.1.2308 (latest FedRAMP release), 9.1.2312


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters