Deployment Architecture

How should I configure outputs.conf on the forwarder in my indexer cluster environment with Local and Global Traffic Managers?

sim_tcr
Communicator

Hello,

We have 4 indexers setup as a cluster with 2 of each indexers behind 2 Local Traffic Managers (LTM). These 2 LTMs are behind a Global Traffic Manager (GTM).

What should we specify in our forwarder outputs.conf so that even if one or more indexers is down, data should be going to other available indexers?

Should we specify the GTM?

Thanks,
SImon Mandy

0 Karma

muebel
SplunkTrust
SplunkTrust

If you configure the outputs.conf to use the GTM as the server, this should accomplish what you want.

All all the indexers in the same datacenter? My sense from your setup is that you have a pair of indexers in two datacenters, in which case you will want the forwarders to only forward to the appropriate LTM.

0 Karma

sim_tcr
Communicator

I had tried configuring the gtm in outputs.conf and forwarder started sending data to one of the indexers.
And then I brought down that very specific indexer to check if forwarder will start sending data to one of other available indexer.
It did not. splunkd.log was telling cannot connect to the indexer (which i brought down)

What are the other option i have?

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...