Related to the use of SC4S_USE_NAME_CACHE=yes After an old DNS Entry was deleted from our DNS service I noticed that I was still getting events indexed in splunk with hostnames...
While working through an issue with a single source that's bursting to 100k events/second over 3 minutes, Bazsi chimed in with the suggestion that jemalloc should help reduce fragmentation, particularly...
the enhancement needed is the port reuse number and buffer size should be specific the the port_id and port type (TCP,UDP,TLS etc) and fall back to the current global value...