<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Load Balance Priorities in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Load-Balance-Priorities/m-p/56765#M1895</link>
    <description>&lt;P&gt;Okay, stick with me on this one.  Take a scenario where I have two sites, one a central datacenter and the other a remote office location connected via a somewhat congested WAN.  I also have two indexers at each location with distributed search pointing to all four.  What I would like to configure is the forwarders at the remote location always try to send their data to the closest indexer (i.e. not transverse the WAN), but if both of the local indexers are down then I want the forwarder to attempt to send the data to the indexers at the datacenter.  In a nutshell I want the forwarders to prioritize one group of indexers over another group.  This is important for us in terms of indexing audit data that &lt;EM&gt;must&lt;/EM&gt; be indexed somewhere.  Is this possible?&lt;/P&gt;

&lt;P&gt;Any input would be appreciated.&lt;/P&gt;</description>
    <pubDate>Tue, 11 Sep 2012 16:53:10 GMT</pubDate>
    <dc:creator>chrislymanWMT1</dc:creator>
    <dc:date>2012-09-11T16:53:10Z</dc:date>
    <item>
      <title>Load Balance Priorities</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Load-Balance-Priorities/m-p/56765#M1895</link>
      <description>&lt;P&gt;Okay, stick with me on this one.  Take a scenario where I have two sites, one a central datacenter and the other a remote office location connected via a somewhat congested WAN.  I also have two indexers at each location with distributed search pointing to all four.  What I would like to configure is the forwarders at the remote location always try to send their data to the closest indexer (i.e. not transverse the WAN), but if both of the local indexers are down then I want the forwarder to attempt to send the data to the indexers at the datacenter.  In a nutshell I want the forwarders to prioritize one group of indexers over another group.  This is important for us in terms of indexing audit data that &lt;EM&gt;must&lt;/EM&gt; be indexed somewhere.  Is this possible?&lt;/P&gt;

&lt;P&gt;Any input would be appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2012 16:53:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Load-Balance-Priorities/m-p/56765#M1895</guid>
      <dc:creator>chrislymanWMT1</dc:creator>
      <dc:date>2012-09-11T16:53:10Z</dc:date>
    </item>
    <item>
      <title>Re: Load Balance Priorities</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Load-Balance-Priorities/m-p/56766#M1896</link>
      <description>&lt;P&gt;This is not currently possible. I'd recommend you have the local forwarders send to their local indexers all the time. &lt;/P&gt;

&lt;P&gt;If you have available resources, you could do the following:&lt;/P&gt;

&lt;P&gt;DC1Forwarders -&amp;gt; datacenter1indexer1 -&amp;gt; datacenter2indexer1&lt;BR /&gt;
DC2Forwarders -&amp;gt; datacenter2indexer2 -&amp;gt; datacenter1indexer2&lt;/P&gt;

&lt;P&gt;This way the forwarders always talk to their local indexers, then the indexers do the forwarding over the WAN link to each other, allowing you to better configure queueing on the indexers instead of on the forwarders. This also allows you to set up two HA searchheads, one in datacenter1 peered to datacenter1's indexers, and one in datacenter2 peered to datacenter2's indexers. &lt;/P&gt;

&lt;P&gt;This is the recommended way of doing HA across datacenters, until Splunk releases multi-datacenter replication. &lt;/P&gt;</description>
      <pubDate>Thu, 13 Sep 2012 04:46:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Load-Balance-Priorities/m-p/56766#M1896</guid>
      <dc:creator>adamw</dc:creator>
      <dc:date>2012-09-13T04:46:45Z</dc:date>
    </item>
    <item>
      <title>Re: Load Balance Priorities</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Load-Balance-Priorities/m-p/56767#M1897</link>
      <description>&lt;P&gt;If this doesn't make sense, I can draw a better ascii diagram.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Sep 2012 04:47:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Load-Balance-Priorities/m-p/56767#M1897</guid>
      <dc:creator>adamw</dc:creator>
      <dc:date>2012-09-13T04:47:29Z</dc:date>
    </item>
  </channel>
</rss>

