Splunk Kafka Connect collapses when HEC ack latency outruns the consumer timeout
Shows how to fix splunk Kafka Connect collapses when HEC ack latency outruns the consumer timeout. Use it when you hit this exact problem. Skip it when your error message or symptom looks different.
TL;DR
Change one limit at a time and watch rebalance frequency, acknowledgment latency, and connector lag. Keep tasks.max at or below the partition count to avoid duplicates on fresh connectors.
Steps
- Change one limit at a time and watch rebalance frequency, acknowledgment latency, and connector lag. Check license limits and quotas before tuning timeouts, since throttled indexing looks identical to a slow consumer. Keep tasks.max at or below the partition count to avoid duplicates on fresh connectors.
When to use
Use this skill when you run into "Splunk Kafka Connect collapses when HEC ack latency outruns the consumer timeout".
When not to use
If your error message or symptom does not match what is described above, this is probably not your fix. Search for your exact error text instead of forcing this one to fit.
Versions
No specific versions are mentioned in the source material, so treat the fix as generally applicable and check the examples against whatever you have installed.
Why this happens
The original report does not dig into a root cause. It documents the symptom and the fix that resolved it.