<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How does Splunk Universal Forwarder behave for load balanced deployment toplogies when Receivers are down? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-Universal-Forwarder-behave-for-load-balanced/m-p/308281#M58059</link>
    <description>&lt;P&gt;I did read this before posting. The actual statement, i wanted to understand from that document was&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;In all these cases, the forwarder will then attempt to open a connection to the next indexer in the load-balanced group, or to the same indexer again if load-balancing is not enabled.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;But I'm not sure whats the impact of having continous non-reachable/timeout indexers&lt;/P&gt;</description>
    <pubDate>Tue, 23 May 2017 14:37:21 GMT</pubDate>
    <dc:creator>koshyk</dc:creator>
    <dc:date>2017-05-23T14:37:21Z</dc:date>
    <item>
      <title>How does Splunk Universal Forwarder behave for load balanced deployment toplogies when Receivers are down?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-Universal-Forwarder-behave-for-load-balanced/m-p/308277#M58055</link>
      <description>&lt;P&gt;one of the customers have a situation whereby there are 1000's of clients with Universal Forwarders in multiple network zones , trying to reach Splunk Heavy Forwarders which are also in multiple network  zones.  The network zones has to be specific due to security controls, but it is very hard to determine which zone the client (UF) beforehand.  As of now, the outputs.conf are hand-crafted manually once the customer identifies which zone the UF is based upon. &lt;BR /&gt;
I was thinking to push outputs.conf with &lt;STRONG&gt;All&lt;/STRONG&gt; Heavy-forwarder-servers in outputs.conf, but I'm sure some of these cannot be reached from the clients.  So my question is&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;How does the UF load-balance behave when it has all (say 10) servers in its outputs.conf list, but only can reach a subset (say 4) of them?&lt;/LI&gt;
&lt;LI&gt;Will it throw error and cause failure on the client? or lot of error logs?&lt;/LI&gt;
&lt;LI&gt;Is there mechanism whereby we can ask the UF not to try the receiver again if it fails N number of times?&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Tue, 23 May 2017 13:48:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-Universal-Forwarder-behave-for-load-balanced/m-p/308277#M58055</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2017-05-23T13:48:55Z</dc:date>
    </item>
    <item>
      <title>Re: How does Splunk Universal Forwarder behave for load balanced deployment toplogies when Receivers are down?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-Universal-Forwarder-behave-for-load-balanced/m-p/308278#M58056</link>
      <description>&lt;P&gt;This documentation page has everything you need to answer you own question.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/6.6.0/Forwarding/Protectagainstlossofin-flightdata"&gt;https://docs.splunk.com/Documentation/Splunk/6.6.0/Forwarding/Protectagainstlossofin-flightdata&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2017 13:59:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-Universal-Forwarder-behave-for-load-balanced/m-p/308278#M58056</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-05-23T13:59:38Z</dc:date>
    </item>
    <item>
      <title>Re: How does Splunk Universal Forwarder behave for load balanced deployment toplogies when Receivers are down?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-Universal-Forwarder-behave-for-load-balanced/m-p/308279#M58057</link>
      <description>&lt;P&gt;It will generate timeout logs and then move on to the next indexer.  The built-in load-balancing does not provide a way to automatically stop trying an Indexer that is continuously down.&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2017 14:16:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-Universal-Forwarder-behave-for-load-balanced/m-p/308279#M58057</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-05-23T14:16:38Z</dc:date>
    </item>
    <item>
      <title>Re: How does Splunk Universal Forwarder behave for load balanced deployment toplogies when Receivers are down?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-Universal-Forwarder-behave-for-load-balanced/m-p/308280#M58058</link>
      <description>&lt;P&gt;I hope that means, all the data will be intact but will have errors in the UF logs?&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2017 14:34:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-Universal-Forwarder-behave-for-load-balanced/m-p/308280#M58058</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2017-05-23T14:34:39Z</dc:date>
    </item>
    <item>
      <title>Re: How does Splunk Universal Forwarder behave for load balanced deployment toplogies when Receivers are down?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-Universal-Forwarder-behave-for-load-balanced/m-p/308281#M58059</link>
      <description>&lt;P&gt;I did read this before posting. The actual statement, i wanted to understand from that document was&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;In all these cases, the forwarder will then attempt to open a connection to the next indexer in the load-balanced group, or to the same indexer again if load-balancing is not enabled.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;But I'm not sure whats the impact of having continous non-reachable/timeout indexers&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2017 14:37:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-Universal-Forwarder-behave-for-load-balanced/m-p/308281#M58059</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2017-05-23T14:37:21Z</dc:date>
    </item>
    <item>
      <title>Re: How does Splunk Universal Forwarder behave for load balanced deployment toplogies when Receivers are down?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-Universal-Forwarder-behave-for-load-balanced/m-p/308282#M58060</link>
      <description>&lt;P&gt;No data loss, but possibly data duplication (very unlikely), unless you &lt;CODE&gt;useAck&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2017 14:54:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-Universal-Forwarder-behave-for-load-balanced/m-p/308282#M58060</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-05-23T14:54:25Z</dc:date>
    </item>
    <item>
      <title>Re: How does Splunk Universal Forwarder behave for load balanced deployment toplogies when Receivers are down?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-Universal-Forwarder-behave-for-load-balanced/m-p/308283#M58061</link>
      <description>&lt;P&gt;Is this the same for if an indexer has full disk?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Nov 2019 18:33:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-Universal-Forwarder-behave-for-load-balanced/m-p/308283#M58061</guid>
      <dc:creator>ridwanahmed</dc:creator>
      <dc:date>2019-11-11T18:33:13Z</dc:date>
    </item>
    <item>
      <title>Re: How does Splunk Universal Forwarder behave for load balanced deployment toplogies when Receivers are down?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-Universal-Forwarder-behave-for-load-balanced/m-p/308284#M58062</link>
      <description>&lt;P&gt;Yes, the indexer should put itself into detention/quarantine.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2019 01:31:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-Universal-Forwarder-behave-for-load-balanced/m-p/308284#M58062</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-11-12T01:31:56Z</dc:date>
    </item>
  </channel>
</rss>

