All Apps and Add-ons

REST API Modular input app and Distributed deployment

be910j
Path Finder

Curious if anyone has found a good way to deal with this issue.

I currently have a distributed deployment with 6 active Indexers. Currently testing the REST API Modular Input app on a single instance test box and its working great but I want to move it over to my prod environment now and put it into our distributed model.
With just the polling model and no cron option (that I saw) is there a way I can keep the data distributed across my multi indexers easily or is it more along the lines of using a single box to make the initial grab/index and forward that data over to my indexer farm for distribution, or maybe setting the polling time on each indexer in such a way that they won't overlap, though Im not sure what kind of combination that would be and would prob grow to be quite complex I would assume?Heavy forwarder and a dedicated API Collection server- VM maybe? Just wandering if there was a preferred method or what people have found success with.

Cheers,
Brandon

1 Solution

be910j
Path Finder

Well just to post a follow up here, while I'm not positive if it's the best way, I ended up building a heavy forwarder to do all the work and send the cooked data over to my indexers, so far seems to be working ok.

-brandon

View solution in original post

Damien_Dallimor
Ultra Champion

There's no distributed co-ordination logic in the REST API Modular Input , so they way you have approached it is probably the best option.

0 Karma

be910j
Path Finder

Well just to post a follow up here, while I'm not positive if it's the best way, I ended up building a heavy forwarder to do all the work and send the cooked data over to my indexers, so far seems to be working ok.

-brandon

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Index This | How many sevens are there between 1 and 100?

August 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Enhance Security Operations with Automated Threat Analysis in the Splunk EcosystemAre you leveraging ...

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...