Deployment Architecture

Light forwarder behavior when one indexer is down (autolb disabled)

anantshah
Path Finder

Hello,

We are currently using light forwarders on our web boxes to forward iis logs to two indexers. One of the indexers went down and when it came back up, it did not receive data from during the outage. The 2nd indexer did not have any problems. Is this expected behavior? Does the forwarder buffer events for one indexer if the second one is up? Both indexers are independent.

Tags (1)
0 Karma
1 Solution

the_wolverine
Champion

In a cloning situation, if one indexer were to go down, Splunk will not buffer the events. As you have experienced, it will continue to send events to the other indexer.

http://www.splunk.com/wiki/Community:HighAvailabilityAndSplunk

There is the issue where the data on your indexers will be out-of-sync when such a situation arises.

View solution in original post

0 Karma

the_wolverine
Champion

In a cloning situation, if one indexer were to go down, Splunk will not buffer the events. As you have experienced, it will continue to send events to the other indexer.

http://www.splunk.com/wiki/Community:HighAvailabilityAndSplunk

There is the issue where the data on your indexers will be out-of-sync when such a situation arises.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...