<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: useack in distributed environment 2 sets of heavy forwaders in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/useack-in-distributed-environment-2-sets-of-heavy-forwaders/m-p/555359#M6103</link>
    <description>&lt;P&gt;Hi&lt;BR /&gt;it’s exactly that way. You should use that same settings on all your uf + hf nodes to take it really into use.&amp;nbsp;&lt;BR /&gt;Did you know that your placement is not as Splunk’s best practices said. Optimal configuration is avoid HFS between UFs and indexers.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
    <pubDate>Thu, 10 Jun 2021 17:48:55 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2021-06-10T17:48:55Z</dc:date>
    <item>
      <title>useack in distributed environment 2 sets of heavy forwaders</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/useack-in-distributed-environment-2-sets-of-heavy-forwaders/m-p/555274#M6093</link>
      <description>&lt;P&gt;Hi Splunk Support!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We currently have a large Distributed Envirionment where we have 3 sets of Heavy forwarders which have 2 nodes, before hitting an indexer.&lt;/P&gt;&lt;P&gt;Set HFWA --&amp;gt; Has 2 Heavy forwarders&lt;/P&gt;&lt;P&gt;Set HFWB --&amp;gt; has 2 heavy forwarders&amp;nbsp;&lt;/P&gt;&lt;P&gt;Set HFWC --&amp;gt; has 2 heavy forwarders&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The data flow goes HFWA ---&amp;gt; HFWB ---&amp;gt; HFWC ---&amp;gt; Indexer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HFWA outputs.conf has useACK=true.&lt;/P&gt;&lt;P&gt;HFWB &amp;amp; HFWC have useACK=false.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So&lt;/P&gt;&lt;P&gt;The data flow goes HFWA (useACK=true) ---&amp;gt; HFWB (useACK=false) ---&amp;gt; HFWC(useACK=false) ---&amp;gt; Indexer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the expected output? Will HFWB Give an acknowledgement back to HFWA?&lt;/P&gt;&lt;P&gt;Is this an issue in our environment?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Craig&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jun 2021 09:18:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/useack-in-distributed-environment-2-sets-of-heavy-forwaders/m-p/555274#M6093</guid>
      <dc:creator>craigwilkinson</dc:creator>
      <dc:date>2021-06-10T09:18:44Z</dc:date>
    </item>
    <item>
      <title>Re: useack in distributed environment 2 sets of heavy forwaders</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/useack-in-distributed-environment-2-sets-of-heavy-forwaders/m-p/555359#M6103</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;it’s exactly that way. You should use that same settings on all your uf + hf nodes to take it really into use.&amp;nbsp;&lt;BR /&gt;Did you know that your placement is not as Splunk’s best practices said. Optimal configuration is avoid HFS between UFs and indexers.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jun 2021 17:48:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/useack-in-distributed-environment-2-sets-of-heavy-forwaders/m-p/555359#M6103</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-06-10T17:48:55Z</dc:date>
    </item>
    <item>
      <title>Re: useack in distributed environment 2 sets of heavy forwaders</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/useack-in-distributed-environment-2-sets-of-heavy-forwaders/m-p/555392#M6106</link>
      <description>&lt;P&gt;Hi could you please explain by "its exactly that way"&lt;/P&gt;&lt;P&gt;If 2 sets of our heavy forwarders have useACK... but 1 of of the set of Heavy Forwarders doesnt have useACK before indexing.. what happens? Will the first 2 set of Heavy forwarders continue to hold the data until an ACK is recieved? Which I assume it enver will, because HFWC doesnt have this enabled?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jun 2021 23:44:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/useack-in-distributed-environment-2-sets-of-heavy-forwaders/m-p/555392#M6106</guid>
      <dc:creator>craigwilkinson</dc:creator>
      <dc:date>2021-06-10T23:44:42Z</dc:date>
    </item>
  </channel>
</rss>

