<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can you help me with communication and distribution of information from the universal forwarder to Indexer (cluster)? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Can-you-help-me-with-communication-and-distribution-of/m-p/389796#M69763</link>
    <description>&lt;P&gt;Good Morning,&lt;/P&gt;

&lt;P&gt;We have the following concern. We currently have several universal forwarders sending information to the indexers, but we see that some servers have outdated information in the outputs.conf.&lt;/P&gt;

&lt;P&gt;for example&lt;BR /&gt;
&amp;nbsp;&amp;nbsp;&lt;BR /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;The current configuration of our cluster is 6 indexer&lt;BR /&gt;
[tcpout]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
defaultGroup = indexCluster&lt;/P&gt;

&lt;P&gt;[tcpout: indexCluster]&lt;BR /&gt;
useACK = true&lt;BR /&gt;
server = x.x.x.1: 9999, x.x.x.2: 9999, x.x.x.3: 9999, x.x.x.4: 9999, x.x.x.5: 9999, x.x.x.6: 9999&lt;/P&gt;

&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;And certain servers have only some&lt;BR /&gt;
[tcpout]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
defaultGroup = indexCluster&lt;/P&gt;

&lt;P&gt;[tcpout: indexCluster]&lt;BR /&gt;
useACK = true&lt;BR /&gt;
server = x.x.x.1: 9999, x.x.x.2: 9999, x.x.x.3: 9999, x.x.x.4: 9999&lt;/P&gt;

&lt;P&gt;1- Is there any problem if all the machines are not defined in the outputs.conf?&lt;/P&gt;

&lt;P&gt;2- We see an overload in some indexer, will it be because all the indexers in our universal forwarder are not defined?&lt;/P&gt;

&lt;P&gt;3- When the UF sends information to the cluster, it will be sent by the first IP that establishes communication or the cluster assigns which machine will take this task.&lt;/P&gt;

&lt;P&gt;4- What happens when the cluster has a lot of load in an indexer, for example indexer 1 (xxx1: 9999) . Does the cluster perform a balancing and designate another indexer for this task? But if my only forwarder has only that IP pointing, how will i know that the idx2, or idx3 are without less loads, if i do not have these ip defined (xxx2: 9999, xxx3: 9999) in the outputs.conf?&lt;/P&gt;

&lt;P&gt;Any information is appreciated&lt;/P&gt;

&lt;P&gt;regards&lt;/P&gt;</description>
    <pubDate>Fri, 28 Dec 2018 14:27:11 GMT</pubDate>
    <dc:creator>efaundez</dc:creator>
    <dc:date>2018-12-28T14:27:11Z</dc:date>
    <item>
      <title>Can you help me with communication and distribution of information from the universal forwarder to Indexer (cluster)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-you-help-me-with-communication-and-distribution-of/m-p/389796#M69763</link>
      <description>&lt;P&gt;Good Morning,&lt;/P&gt;

&lt;P&gt;We have the following concern. We currently have several universal forwarders sending information to the indexers, but we see that some servers have outdated information in the outputs.conf.&lt;/P&gt;

&lt;P&gt;for example&lt;BR /&gt;
&amp;nbsp;&amp;nbsp;&lt;BR /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;The current configuration of our cluster is 6 indexer&lt;BR /&gt;
[tcpout]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
defaultGroup = indexCluster&lt;/P&gt;

&lt;P&gt;[tcpout: indexCluster]&lt;BR /&gt;
useACK = true&lt;BR /&gt;
server = x.x.x.1: 9999, x.x.x.2: 9999, x.x.x.3: 9999, x.x.x.4: 9999, x.x.x.5: 9999, x.x.x.6: 9999&lt;/P&gt;

&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;And certain servers have only some&lt;BR /&gt;
[tcpout]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
defaultGroup = indexCluster&lt;/P&gt;

&lt;P&gt;[tcpout: indexCluster]&lt;BR /&gt;
useACK = true&lt;BR /&gt;
server = x.x.x.1: 9999, x.x.x.2: 9999, x.x.x.3: 9999, x.x.x.4: 9999&lt;/P&gt;

&lt;P&gt;1- Is there any problem if all the machines are not defined in the outputs.conf?&lt;/P&gt;

&lt;P&gt;2- We see an overload in some indexer, will it be because all the indexers in our universal forwarder are not defined?&lt;/P&gt;

&lt;P&gt;3- When the UF sends information to the cluster, it will be sent by the first IP that establishes communication or the cluster assigns which machine will take this task.&lt;/P&gt;

&lt;P&gt;4- What happens when the cluster has a lot of load in an indexer, for example indexer 1 (xxx1: 9999) . Does the cluster perform a balancing and designate another indexer for this task? But if my only forwarder has only that IP pointing, how will i know that the idx2, or idx3 are without less loads, if i do not have these ip defined (xxx2: 9999, xxx3: 9999) in the outputs.conf?&lt;/P&gt;

&lt;P&gt;Any information is appreciated&lt;/P&gt;

&lt;P&gt;regards&lt;/P&gt;</description>
      <pubDate>Fri, 28 Dec 2018 14:27:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-you-help-me-with-communication-and-distribution-of/m-p/389796#M69763</guid>
      <dc:creator>efaundez</dc:creator>
      <dc:date>2018-12-28T14:27:11Z</dc:date>
    </item>
    <item>
      <title>Re: Can you help me with communication and distribution of information from the universal forwarder to Indexer (cluster)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-you-help-me-with-communication-and-distribution-of/m-p/389797#M69764</link>
      <description>&lt;P&gt;Hi @efaundez,&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Yes, if you do not define all Indexers servers on all UFs then data load balanced between Indexer servers are not balanced.&lt;/LI&gt;
&lt;LI&gt;It might due to this, let's say there are few UFs which has only 4 Indexers in their outputs.conf and they are generating huge amount of data in that case only 4 Indexers will parse those data and due to that there might be possibility that those 4 Indexers are overloaded however remaining 2 Indexer servers have less load compare to other 4.&lt;/LI&gt;
&lt;LI&gt;Based on documentation , server will be randomly pick up Indexer server&lt;/LI&gt;
&lt;/OL&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;autoLBFrequency = &lt;BR /&gt;
   * The amount of time, in seconds, that a forwarder sends data to an indexer before redirecting outputs to another indexer in the pool. * Use this setting when you are using automatic load balancing of outputs from universal forwarders (UFs). * Every 'autoLBFrequency' seconds, a new indexer is selected randomly from the list of indexers provided in the server setting of the target group stanza.&lt;BR /&gt;
   * Default: 30&lt;BR /&gt;
4. If you have only 1 Indexer defined in outputs.conf and if indexer is overloaded and stop receiving data in that case UF will queue data in waitqueue because you are using &lt;CODE&gt;useACK=true&lt;/CODE&gt;, once wait queue fills up UF will stop sending data to Indexer until Acknowledgement receives back from Indexer . Ref document &lt;A href="https://docs.splunk.com/Documentation/Forwarder/7.2.3/Forwarder/Protectagainstthelossofin-flightdata#How_indexer_acknowledgment_works_when_a_failure_occurs"&gt;https://docs.splunk.com/Documentation/Forwarder/7.2.3/Forwarder/Protectagainstthelossofin-flightdata#How_indexer_acknowledgment_works_when_a_failure_occurs&lt;/A&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Fri, 28 Dec 2018 14:53:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-you-help-me-with-communication-and-distribution-of/m-p/389797#M69764</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2018-12-28T14:53:11Z</dc:date>
    </item>
  </channel>
</rss>

