<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Heavy Forwarder and Loadbalancing in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarder-and-Loadbalancing/m-p/87699#M18211</link>
    <description>&lt;P&gt;What would be the expected behavior?&lt;/P&gt;</description>
    <pubDate>Tue, 19 Mar 2013 19:04:13 GMT</pubDate>
    <dc:creator>the_wolverine</dc:creator>
    <dc:date>2013-03-19T19:04:13Z</dc:date>
    <item>
      <title>Heavy Forwarder and Loadbalancing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarder-and-Loadbalancing/m-p/87695#M18207</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;Here at my company we have one search head and three indexers.... We have a standalone server that has an Heavy Forwarder installed, we have a script on the server that is polling a database and sending the data to the forwarder through a TCP stream which gets indexed and forwarded to the indexers. The problem we are having is that the heavy forwarder is not properly distributing the data across the indexers and instead is sending everything to only one indexer... what should we do to solve this problem?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2013 14:17:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarder-and-Loadbalancing/m-p/87695#M18207</guid>
      <dc:creator>ivantn21</dc:creator>
      <dc:date>2013-01-15T14:17:25Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarder and Loadbalancing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarder-and-Loadbalancing/m-p/87696#M18208</link>
      <description>&lt;P&gt;How did you set up load balancing ? Does load balancing work for other sourcetypes forwarded by the heavy forwarder ?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2013 15:37:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarder-and-Loadbalancing/m-p/87696#M18208</guid>
      <dc:creator>jonuwz</dc:creator>
      <dc:date>2013-01-15T15:37:31Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarder and Loadbalancing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarder-and-Loadbalancing/m-p/87697#M18209</link>
      <description>&lt;P&gt;I just edited the ouputs.conf to foward to three indexers and it does work for all sourcetypes it just don't load balance across the three indexers...&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2013 15:51:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarder-and-Loadbalancing/m-p/87697#M18209</guid>
      <dc:creator>ivantn21</dc:creator>
      <dc:date>2013-01-15T15:51:39Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarder and Loadbalancing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarder-and-Loadbalancing/m-p/87698#M18210</link>
      <description>&lt;P&gt;ivantn21, can you post your outputs.conf?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2013 15:54:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarder-and-Loadbalancing/m-p/87698#M18210</guid>
      <dc:creator>mloven_splunk</dc:creator>
      <dc:date>2013-01-15T15:54:59Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarder and Loadbalancing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarder-and-Loadbalancing/m-p/87699#M18211</link>
      <description>&lt;P&gt;What would be the expected behavior?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2013 19:04:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarder-and-Loadbalancing/m-p/87699#M18211</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2013-03-19T19:04:13Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarder and Loadbalancing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarder-and-Loadbalancing/m-p/87700#M18212</link>
      <description>&lt;P&gt;I believe that the problem is that it is a TCP stream. The autolb can't make the stream break. We see the same issue with routers sending data to a forwarder which load balances between 3 indexers.  You will most likely notice that if you restart the splunk instance on the one indexer that is getting all the tcp stream data that it will change to the next one.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2013 19:39:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarder-and-Loadbalancing/m-p/87700#M18212</guid>
      <dc:creator>jfraiberg</dc:creator>
      <dc:date>2013-04-15T19:39:19Z</dc:date>
    </item>
  </channel>
</rss>

