Splunk Enterprise

put splunk heavy forwarders behind loadbalancer

raindrop18
Communicator

I have multiple heavy-forwarders and currently they are behind AWS route 53 DNS, and I am thinking if I get a benefit if I move the heavy forwarders behind loadbalancer. apperciate any feedback and if any related document about this highly appreciate it.

Tags (1)
0 Karma
1 Solution

somesoni2
Revered Legend

Splunk doesn't recommend setting up external load balance between forwarder (universal fwd in your case, I assume) and receiver (Intermediate Heavy fwd in your case, I assume). (see note on paragraph 1)

https://docs.splunk.com/Documentation/Forwarder/7.0.1/Forwarder/Configureloadbalancing

View solution in original post

somesoni2
Revered Legend

Splunk doesn't recommend setting up external load balance between forwarder (universal fwd in your case, I assume) and receiver (Intermediate Heavy fwd in your case, I assume). (see note on paragraph 1)

https://docs.splunk.com/Documentation/Forwarder/7.0.1/Forwarder/Configureloadbalancing

raindrop18
Communicator

thanks very help full information.

0 Karma

gwalford
Path Finder

Why do you feel you would get a benefit from a load balancer? By default, the forwarders switch indexers every 30 seconds. This happens when the forwarder detects and End of File.

Load Balancing like this is the key to making distributed search or clustering work.

http://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Setuploadbalancingd

Now, you do want to do this for search heads, and syslog-ng data, but that is a different topic.

raindrop18
Communicator

thanks for response. that answer my question!!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...