Skip to content

Commit d1d1ace

Browse files
author
“deep-splunk”
committed
docs(readme): update definition of splunk.hec.backoff.threshhold.seconds
1 parent e853a89 commit d1d1ace

File tree

1 file changed

+8
-1
lines changed

1 file changed

+8
-1
lines changed

README.md

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -173,7 +173,7 @@ Use the below schema to configure Splunk Connect for Kafka
173173
| `splunk.hec.json.event.formatted` | Set to `true` for events that are already in HEC format. Valid settings are `true` or `false`. |`false`|
174174
| `splunk.hec.max.outstanding.events` | Maximum amount of un-acknowledged events kept in memory by connector. Will trigger back-pressure event to slow down collection if reached. | `1000000` |
175175
| `splunk.hec.max.retries` | Amount of times a failed batch will attempt to resend before dropping events completely. Warning: This will result in data loss, default is `-1` which will retry indefinitely | `-1` |
176-
| `splunk.hec.backoff.threshhold.seconds` | The amount of time Splunk Connect for Kafka waits to attempt resending after errors from a HEC endpoint." | `60` |
176+
| `splunk.hec.backoff.threshhold.seconds` | The amount of duration the Indexer will be stopped after getting error code while posting the data.</br> **NOTE:** <br/> Other Indexer won't get affected with this parameter." | `60` |
177177
| `splunk.hec.lb.poll.interval` | Specify this parameter(in seconds) to control the polling interval(increase to do less polling, decrease to do more frequent polling, set `-1` to disable polling) | `120` |
178178
| `splunk.hec.enable.compression` | Valid settings are true or false. Used for enable or disable gzip-compression. |`false`|
179179
### Acknowledgement Parameters
@@ -232,6 +232,13 @@ Use the below schema to configure Splunk Connect for Kafka
232232
| `timestamp.regex` | Regex for timestamp extraction. <br/> **NOTE:** <br/> Regex must have name captured group `"time"` For eg.: `\\\"time\\\":\\s*\\\"(?<time>.*?)\"` | `""` |
233233
| `timestamp.format` | Time-format for timestamp extraction .<br/>For eg.: <br/>If timestamp is `1555209605000` , set `timestamp.format` to `"epoch"` format .<br/> If timestamp is `Jun 13 2010 23:11:52.454 UTC` , set `timestamp.format` to `"MMM dd yyyy HH:mm:ss.SSS zzz"` | `""` |
234234

235+
### Out-of-band Health Checks and In-band Health Checks
236+
| Health Checks | Description |
237+
|-------- |----------------------------|
238+
| `Out of band health check` | This health check targets Loadbalancer and aims to remove all the unhealthy channels from the pool; all channels are released for the configurable period using the parameter `splunk.hec.lb.poll.interval`, some that may be otherwise healthy. Although this is configurable (by default 120 seconds), It may still get a 503 result code from the indexer. For that, there is another health check, and it can be called the in-band-health check. |
239+
| `In band healthcheck` | This health check targets Indexer while posting data. If an error code is received, then it will trigger this health check. When this check fails, It will Pause the indexing from the Particular Indexer for a configurable time using the parameter `Splunk.hec.backoff.threshhold.seconds` and trigger backpressure handling So that event that could not be indexed will be retried again. |
240+
241+
235242
## Load balancing
236243

237244
See [Splunk Docs](https://docs.splunk.com/Documentation/KafkaConnect/latest/User/LoadBalancing) for considerations when using load balancing in your deployment.

0 commit comments

Comments
 (0)