Getting Data In

Can a forwarder be configured to two indexers without load balancing?

mce128
Explorer

I have tried quite unsuccessfully to search for an answer to achieve this configuration, so I'm asking here. Hopefully someone has a suggestion/solution to my kind of unusual configuration requirement.

Is it possible to configure a forwarder to send to two separate indexers without load balancing, so that both indexers receive all the data independently?

I understand this is an atypical situation, however, this is something I need to achieve. The indexers will be unable to communicate with each other and will be combined indexer/search heads, so they can't share the received data or be searched in a distributed fashion.

I would suppose it would be possible to run two forwarders on the monitored host(s) one forwarding out to each indexer, but this would be a I/O hog and wasteful of system resources. As a result it would be highly desirable to send to both indexers from a single instance of the forwarder on the monitored host.

Has anyone done this? Is it even possible?

Thanks,
Joe

1 Solution

mce128
Explorer

WOW... Don't know how I missed THAT in the docs...

Thanks!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...