<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: We built a new indexer cluster and trying to reroute some of the ingestion from current cluster to new cluster in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/We-built-a-new-indexer-cluster-and-trying-to-reroute-some-of-the/m-p/532512#M4394</link>
    <description>&lt;P&gt;Check if the new indexers have receiver enabled correctly:&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.0/Forwarding/Enableareceiver" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.0/Forwarding/Enableareceiver&lt;/A&gt;&lt;/P&gt;&lt;P&gt;See if you could send some dummy non-internal data from cluster master (using add oneshot method OR HEC).&lt;/P&gt;</description>
    <pubDate>Wed, 09 Dec 2020 18:16:26 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2020-12-09T18:16:26Z</dc:date>
    <item>
      <title>We built a new indexer cluster and trying to reroute some of the ingestion from current cluster to new cluster</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/We-built-a-new-indexer-cluster-and-trying-to-reroute-some-of-the/m-p/532507#M4393</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;we built a new cluster as we are getting out of space on current one and we are trying to reroute some of the ingestion to the new cluster by adding the new indexer clusters stanza in the outputs.conf and using _TCP_ROUTING setting in the inputs.conf the servers we want to reroute the ingestion.&amp;nbsp;&lt;/P&gt;&lt;P&gt;below is the stanza we added in outputs.conf&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[tcpout:ABC_indexers] &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Server = &lt;/SPAN&gt;&lt;A href="http://172.16.200.178:9997/" target="_blank" rel="noopener nofollow noreferrer"&gt;xx.xx.xx.xx.xx:9997&lt;/A&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;A href="http://172.16.200.179:9997/" target="_blank" rel="noopener nofollow noreferrer"&gt;xx.xx.xx.xx.xx:9997&lt;/A&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;A href="http://172.16.200.180:9997/" target="_blank" rel="noopener nofollow noreferrer"&gt;xx.xx.xx.xx:9997&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;useACK = true&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;in the inputs.conf we added below setting and pushed it to the servers we want to reroute the data and restarted the forwarder service:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;_TCP_ROUTING =&amp;nbsp;ABC_indexers&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;but we are not seeing any ingestion to the new cluster and we are getting few errors and warning. We checked that the forwarders are connected to all our new indexers over 9997 port.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;WARN TcpOutputProc - The TCP output processor has paused the data flow. Forwarding to output group ABC_indexers has been blocked for 800 seconds. This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;BR /&gt;"INFO ProxyConfig - Failed to initialize https_proxy from server.conf for splunkd. Please make sure that the https_proxy property is set as https_proxy=&lt;A href="http://host:port/" target="_blank" rel="noopener"&gt;http://host:port&lt;/A&gt;&amp;nbsp;in case HTTP proxying needs to be enabled."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;we checked everything on the indexers but could not find out what is blocking the indexers to receive the data. We have cluster master which is ingesting internal logs to this new indexers and that is not having any issue.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Please let me know if anyone got this issue and how you resolved it.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 17:50:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/We-built-a-new-indexer-cluster-and-trying-to-reroute-some-of-the/m-p/532507#M4393</guid>
      <dc:creator>sathwik067</dc:creator>
      <dc:date>2020-12-09T17:50:04Z</dc:date>
    </item>
    <item>
      <title>Re: We built a new indexer cluster and trying to reroute some of the ingestion from current cluster to new cluster</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/We-built-a-new-indexer-cluster-and-trying-to-reroute-some-of-the/m-p/532512#M4394</link>
      <description>&lt;P&gt;Check if the new indexers have receiver enabled correctly:&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.0/Forwarding/Enableareceiver" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.0/Forwarding/Enableareceiver&lt;/A&gt;&lt;/P&gt;&lt;P&gt;See if you could send some dummy non-internal data from cluster master (using add oneshot method OR HEC).&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 18:16:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/We-built-a-new-indexer-cluster-and-trying-to-reroute-some-of-the/m-p/532512#M4394</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2020-12-09T18:16:26Z</dc:date>
    </item>
  </channel>
</rss>

