Splunk Stream

Installation and Configuration Manual

Splunk_TA_stream (UF) test results - default configuration

This page shows performance test results for Splunk_TA_stream (which contains the streamfwd binary) running on universal forwarder (UF) over a variety of workloads. For detailed test environment and configuration information, see Splunk Stream test environments in this manual.

HTTP 100K response test results

Stats 8Mbps 64Mbps 256Mbps 512Mbps 1Gbps 2Gbps 3Gbps 4Gbps
CPU% (splunkd) 2 4 4 3 3 3 4 4
Memory MB (splunkd) 130 131 130 130 163 162 162 161
CPU% (streamfwd) 7 15 32 55 93 183 266 414
Memory MB (streamfwd) 163 174 223 234 308 325 376 5270
Events/sec 41 217 884 1758 3435 6852 10277 14318
Drop Rate % 0 0 0 0 0 0 0 5

HTTP 25K response test results

Stats 8Mbps 64Mbps 256Mbps 512Mbps 1Gbps 2Gbps 3Gbps 4Gbps
CPU% (splunkd) 4 4 4 4 4 4 3 5
Memory MB (splunkd) 126 126 125 125 162 162 162 162
CPU% (streamfwd) 8 23 64 118 202 382 364 318
Memory MB (streamfwd) 165 176 219 229 311 428 5987 6126
Events/sec 113 845 3470 6910 13449 26909 20043 12627
Drop Rate % 0 0 0 0 0 0 17 17

HTTPS 100K response test results

Stats 8Mbps 64Mbps 256Mbps 512Mbps 1Gbps 2Gbps 3Gbps 4Gbps
CPU% (splunkd) 2 4 4 3 4 29 34 46
Memory MB (splunkd) 128 129 129 128 167 164 164 167
CPU% (streamfwd) 7 26 78 144 249 387 412 429
Memory MB (streamfwd) 247 298 327 349 468 1504 1871 2114
Events/sec 21 158 431 841 1603 1938 1892 2235
Drop Rate % 0 0 0 0 0 6 15 28

HTTPS 25K response test results

Stats 8Mbps 64Mbps 256Mbps 512Mbps 1Gbps 2Gbps 3Gbps 4Gbps
CPU% (splunkd) 2 3 2 3 3 36 37 36
Memory MB (splunkd) 128 165 165 164 162 161 162 161
CPU% (streamfwd) 7 26 79 149 271 406 441 455
Memory MB (streamfwd) 247 360 387 412 452 1553 1808 2119
Events/sec 22 162 427 831 1597 1927 1971 2294
Drop Rate % 0 0 0 0 0 7 12 23
Last modified on 03 March, 2022
Splunk Stream test environments   Independent streamfwd (HEC) tests - default configuration

This documentation applies to the following versions of Splunk Stream: 8.0.1, 8.0.2, 8.1.0, 8.1.1, 8.1.3

Was this topic useful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters