Splunk Enterprise

how to enable tcp data input in index cluster and how to configure client to forward the data?

sbhaskaran
Explorer

I have a indexer cluster and When I enable tcp data input

How can I ask Master to receive the input?
right now in client conf I am specifying one indexer ip:port but I don't see any replication for the data received.

Any help will be appreciated.

Tags (1)
0 Karma

jwelch_splunk
Splunk Employee
Splunk Employee

repFactor = |auto
* Only relevant if this instance is a clustering slave (but see note about
"auto" below).
* See server.conf spec for details on clustering configuration.
* Value of 0 turns off replication for this index.
* If set to "auto", slave will use whatever value the master has.
* Highest legal value is 4294967295
* Defaults to 0.

Indexes.conf.spec

0 Karma

sbhaskaran
Explorer

@jwelch thanks for answering. repFactor = |auto helps to replicate the index. but still on client I am not able to specify the master host/port so it will send the data to master and it internally load balance it.

0 Karma
Get Updates on the Splunk Community!

Operationalizing TDIR: Building a More Resilient, Scalable SOC

Optimizing SOC workflows with a unified, risk-based approach to Threat Detection, Investigation, and Response ...

Pro Tips for First-Time .conf Attendees: Advice from SplunkTrust

Heading to your first .Conf? You’re in for an unforgettable ride — learning, networking, swag collecting, ...

Raise Your Skills at the .conf25 Builder Bar: Your Splunk Developer Destination

Calling all Splunk developers, custom SPL builders, dashboarders, and Splunkbase app creators – the Builder ...