Splunk ingestion passes through a pipeline of queues: Parsing → Merging → Typing → Indexing. If any queue fills up (`blocked=true` in metrics.log), it creates a bottleneck.
The `parallelIngestionPipelines` setting in `server.conf` can double throughput by running two parallel pipelines on a single indexer, critical for high-volume environments.