<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Heavy forwarder not doing load balancing properly in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-doing-load-balancing-properly/m-p/330310#M61225</link>
    <description>&lt;P&gt;You also need to tell the indexer to listen.  This should be on by default but you can check this:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Forwarder/6.5.2/Forwarder/Enableareceiver"&gt;http://docs.splunk.com/Documentation/Forwarder/6.5.2/Forwarder/Enableareceiver&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 14 Apr 2017 15:28:44 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2017-04-14T15:28:44Z</dc:date>
    <item>
      <title>Heavy forwarder not doing load balancing properly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-doing-load-balancing-properly/m-p/330308#M61223</link>
      <description>&lt;P&gt;I am forwarding data of one log file from 1 Heavy Forwarder to 2 Indexers. But the heavy forwarder is sending data only to Indexer2. &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;- I confirmed it by running query on my searchhead and checking value in field "splunk_server". It was showing just one indexer , i.e Indexer2.&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;OUTPUTS.CONF&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[indexAndForward]
index = false

[tcpout]
defaultGroup = grp
forwardedindex.filter.disable = true

[tcpout:grp]
disabled = 0
# server = 00.000.0.00:9997,00.000.0.00:9997
server = Indexer1:9997,Indexer2:9997
useACK=true
forceTimebasedAutoLB = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;INPUTS.CONF&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///var/log/Folder1/Folder2]
host_segment=5
index=SomeIndex
sourcetype=SomeSourcetype
disabled=0
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;PROPS.CONF&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[SomeSourcetype]
DATETIME_CONFIG =
MAX_TIMESTAMP_LOOKAHEAD = 32
NO_BINARY_CHECK = true
REPORT-syslog = syslog-extractions
SHOULD_LINEMERGE = false
TIME_FORMAT = %b %d %H:%M:%S
TRANSFORMS = syslog-host
category = Operating System
description = Somedescription
disabled = false
maxDist = 3
pulldown_type = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Output of Command - ./splunk list forward-server&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Active forwards:
        Indexer1:9997
        Indexer2.synaptics.com:9997
Configured but inactive forwards:
        None
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I am able to ping to both indexers. Packets are being sent. I checked it through linux command "tcpdump dst indexer1" .&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Please help.&lt;/STRONG&gt;  &lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2017 13:11:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-doing-load-balancing-properly/m-p/330308#M61223</guid>
      <dc:creator>abhinav_maxonic</dc:creator>
      <dc:date>2017-04-14T13:11:01Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy forwarder not doing load balancing properly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-doing-load-balancing-properly/m-p/330309#M61224</link>
      <description>&lt;P&gt;Have you looked in the _internal logs to see what's happening?&lt;/P&gt;

&lt;P&gt;Are there any events like:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;04-14-2017 10:03:46.851 -0400 ERROR TcpOutputFd - Connection to host=Indexer1:9997 failed
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I also noticed that Indexer2 has the FQDN whereas Indexer1 does not.  can your HF resolve both hostnames as you have them specified?&lt;/P&gt;

&lt;P&gt;And are there any firewalls in between the HF and the indexers?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2017 14:06:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-doing-load-balancing-properly/m-p/330309#M61224</guid>
      <dc:creator>jimodonald</dc:creator>
      <dc:date>2017-04-14T14:06:29Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy forwarder not doing load balancing properly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-doing-load-balancing-properly/m-p/330310#M61225</link>
      <description>&lt;P&gt;You also need to tell the indexer to listen.  This should be on by default but you can check this:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Forwarder/6.5.2/Forwarder/Enableareceiver"&gt;http://docs.splunk.com/Documentation/Forwarder/6.5.2/Forwarder/Enableareceiver&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2017 15:28:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-doing-load-balancing-properly/m-p/330310#M61225</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-04-14T15:28:44Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy forwarder not doing load balancing properly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-doing-load-balancing-properly/m-p/330311#M61226</link>
      <description>&lt;P&gt;Hi Jim,&lt;BR /&gt;
I am using FQDN for both indexers. I have edited my question. I checked my splunkd logs , yes this error is present in log . It occurred just once when I have initially set up  this forwarding. &lt;BR /&gt;
So what wrong here ? What should I do  ? &lt;BR /&gt;
I more thing, I am also forwarding some other logs from this HF, it is being load balanced properly two both indexers.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Apr 2017 04:51:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-doing-load-balancing-properly/m-p/330311#M61226</guid>
      <dc:creator>abhinav_maxonic</dc:creator>
      <dc:date>2017-04-17T04:51:08Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy forwarder not doing load balancing properly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-doing-load-balancing-properly/m-p/330312#M61227</link>
      <description>&lt;P&gt;Receiving is enabled. &lt;/P&gt;</description>
      <pubDate>Mon, 17 Apr 2017 04:51:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-doing-load-balancing-properly/m-p/330312#M61227</guid>
      <dc:creator>abhinav_maxonic</dc:creator>
      <dc:date>2017-04-17T04:51:29Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy forwarder not doing load balancing properly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-doing-load-balancing-properly/m-p/330313#M61228</link>
      <description>&lt;P&gt;Here is a better search to use:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_* (9997 OR 9998) (ERR* OR WARN* OR too) source!="*remote_searches.log" source!="*splunkd_ui_access.log"
| rex "(?&amp;lt;indexer&amp;gt;\d+\.\d+\.\d+\.\d+):9997"
| stats count first(_raw) AS first_raw BY punct host indexer
| eval host_count = host . "=" . count
| stats sum(count) AS count first(first_raw) AS first_raw values(host_count) BY punct indexer
| sort 0 - count
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 20 Apr 2017 19:31:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-doing-load-balancing-properly/m-p/330313#M61228</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-04-20T19:31:45Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy forwarder not doing load balancing properly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-doing-load-balancing-properly/m-p/330314#M61229</link>
      <description>&lt;P&gt;I am not getting any of my machine name sending logs or host name listed under "values(host_count)". But I am receiving logs. &lt;BR /&gt;
Do I have to look for anything else in the output of this query ?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2017 09:43:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-doing-load-balancing-properly/m-p/330314#M61229</guid>
      <dc:creator>abhinav_maxonic</dc:creator>
      <dc:date>2017-04-21T09:43:44Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy forwarder not doing load balancing properly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-doing-load-balancing-properly/m-p/330315#M61230</link>
      <description>&lt;P&gt;This query should show you which Indexers are having the most communication problems overall and also specifically with which hosts.  If you don't see your specific hosts in &lt;CODE&gt;values(host_count)&lt;/CODE&gt; then these are not forwarding to the indexers AT ALL.  If that is the case, I suspect that the &lt;CODE&gt;outputs.conf&lt;/CODE&gt; on those hosts does not include those indexers.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2017 16:56:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-doing-load-balancing-properly/m-p/330315#M61230</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-04-21T16:56:05Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy forwarder not doing load balancing properly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-doing-load-balancing-properly/m-p/330316#M61231</link>
      <description>&lt;P&gt;No , my machines are sending data, I can see them on my search head.  Its just for few input monitor it is sending data but not doing the load balancing properly. &lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2017 05:11:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-doing-load-balancing-properly/m-p/330316#M61231</guid>
      <dc:creator>abhinav_maxonic</dc:creator>
      <dc:date>2017-04-24T05:11:44Z</dc:date>
    </item>
  </channel>
</rss>

