<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forwarding from one indexer to another in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Forwarding-from-one-indexer-to-another/m-p/159309#M23198</link>
    <description>&lt;P&gt;No, there is not.&lt;/P&gt;</description>
    <pubDate>Tue, 02 Sep 2014 08:24:22 GMT</pubDate>
    <dc:creator>Ayn</dc:creator>
    <dc:date>2014-09-02T08:24:22Z</dc:date>
    <item>
      <title>Forwarding from one indexer to another</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Forwarding-from-one-indexer-to-another/m-p/159305#M23194</link>
      <description>&lt;P&gt;I have one search-head and two indexers (let's call indexer1 and indexer2). Clients are sending all syslog to indexer1:514. Is it possible to set up forwarding on indexer1, that it will forward half of syslog data to the indexer2? I want to balance that data on two servers.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2013 03:24:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Forwarding-from-one-indexer-to-another/m-p/159305#M23194</guid>
      <dc:creator>bckq</dc:creator>
      <dc:date>2013-11-28T03:24:44Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding from one indexer to another</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Forwarding-from-one-indexer-to-another/m-p/159306#M23195</link>
      <description>&lt;P&gt;Setup a load balancer for the 2 indexers and you will get a load balanced DNS name or IP. &lt;BR /&gt;
Make the Clients to forward data to the load balanced IP or DNS. (This you need to setup in outputs.conf of all the forwarders/Clients)&lt;BR /&gt;
Later , all the forwarders forwards the data to the load-balancer - which takes the job of balancing the load.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2013 06:43:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Forwarding-from-one-indexer-to-another/m-p/159306#M23195</guid>
      <dc:creator>chimbudp</dc:creator>
      <dc:date>2013-11-28T06:43:45Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding from one indexer to another</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Forwarding-from-one-indexer-to-another/m-p/159307#M23196</link>
      <description>&lt;P&gt;The point is that users dont use splunk forwarders to send syslog. They use for example tattle or other stuff that doesn't support loadbalancing and they can set up only one destination address.&lt;BR /&gt;
I was thinking about running splunk forwarder on some machine, set listening on port 514 and then configure forwarding all received data to idexers with parameters:&lt;BR /&gt;
autoLB = true&lt;BR /&gt;
autoLBFrequency = 30&lt;/P&gt;

&lt;P&gt;How about that? Will it work? Is it possible?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2013 23:42:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Forwarding-from-one-indexer-to-another/m-p/159307#M23196</guid>
      <dc:creator>bckq</dc:creator>
      <dc:date>2013-11-28T23:42:47Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding from one indexer to another</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Forwarding-from-one-indexer-to-another/m-p/159308#M23197</link>
      <description>&lt;P&gt;I did the indexing and forwarding with props/transforms/outputs at on indexer and inputs on the destination but it does forward only newly indexed data.&lt;/P&gt;

&lt;P&gt;There´s any way to forward old indexed data right before starting the indexing and forwarding config ?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Sep 2014 08:21:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Forwarding-from-one-indexer-to-another/m-p/159308#M23197</guid>
      <dc:creator>theunf</dc:creator>
      <dc:date>2014-09-02T08:21:58Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding from one indexer to another</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Forwarding-from-one-indexer-to-another/m-p/159309#M23198</link>
      <description>&lt;P&gt;No, there is not.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Sep 2014 08:24:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Forwarding-from-one-indexer-to-another/m-p/159309#M23198</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2014-09-02T08:24:22Z</dc:date>
    </item>
  </channel>
</rss>

