Deployment Architecture

AutoLB Volume

asabatini85
Path Finder

Hi All,

I have 60 indexers and 40 forwarders, I want to set the AutoLB volume, do you know a metric search to calculate a correct value to balance the data load between the indexers?

Tags (1)
0 Karma
1 Solution

p_gurav
Champion

You can use autoLBVolume parameter in outputs.conf. Refer below document for more details:

https://docs.splunk.com/Documentation/Splunk/7.0.3/Admin/Outputsconf

View solution in original post

0 Karma

p_gurav
Champion

You can use autoLBVolume parameter in outputs.conf. Refer below document for more details:

https://docs.splunk.com/Documentation/Splunk/7.0.3/Admin/Outputsconf

0 Karma

asabatini85
Path Finder

Yes, I know the autoLBVolume parameter, I want to know if exist a metric search to calculate how much volume my architecture hold.

0 Karma

p_gurav
Champion

Try using below search:

index="_internal" source="*metrics.log" group="per_host_thruput" | chart sum(kb) by series | sort - sum(kb)

If you want license usage:

 index=_internal source="*license_usage.log" type=usage type=Usage idx=* pool="Your Pool Name" earliest=-30d@d latest=@d
 | eval GB = b
 | timechart limit=50 partial=false span=1d sum(eval(GB/1024/1024/1024)) by idx
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Unlocking Unified Insights: New Gigamon Federated Search App for Splunk

In today’s data-heavy environment, organizations are caught in a data distribution dilemma. As data volumes ...

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...