Deployment Architecture

How should I configure outputs.conf on the forwarder in my indexer cluster environment with Local and Global Traffic Managers?

sim_tcr
Communicator

Hello,

We have 4 indexers setup as a cluster with 2 of each indexers behind 2 Local Traffic Managers (LTM). These 2 LTMs are behind a Global Traffic Manager (GTM).

What should we specify in our forwarder outputs.conf so that even if one or more indexers is down, data should be going to other available indexers?

Should we specify the GTM?

Thanks,
SImon Mandy

0 Karma

muebel
SplunkTrust
SplunkTrust

If you configure the outputs.conf to use the GTM as the server, this should accomplish what you want.

All all the indexers in the same datacenter? My sense from your setup is that you have a pair of indexers in two datacenters, in which case you will want the forwarders to only forward to the appropriate LTM.

0 Karma

sim_tcr
Communicator

I had tried configuring the gtm in outputs.conf and forwarder started sending data to one of the indexers.
And then I brought down that very specific indexer to check if forwarder will start sending data to one of other available indexer.
It did not. splunkd.log was telling cannot connect to the indexer (which i brought down)

What are the other option i have?

0 Karma
Get Updates on the Splunk Community!

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...