Getting Data In

Can we have fewer Heavy Forwarders than Indexers?

hrawat
Splunk Employee
Splunk Employee
 
Labels (1)
0 Karma
1 Solution

hrawat
Splunk Employee
Splunk Employee
 
 
Current practice is to have more Heavy Forwarders than Indexers to keep all indexers busy. However starting 7.3.6 onwards you don't have to. Heavy forwarder can send data to multiple indexers in parallel per ingest pipeline.

 

All you have to set in outputs.conf (maxQueueSize = 5 * autoLBVolume)

Example
autoLBVolume = 5000000
maxQueueSize =25MB

 

View solution in original post

hrawat
Splunk Employee
Splunk Employee
 
 
Current practice is to have more Heavy Forwarders than Indexers to keep all indexers busy. However starting 7.3.6 onwards you don't have to. Heavy forwarder can send data to multiple indexers in parallel per ingest pipeline.

 

All you have to set in outputs.conf (maxQueueSize = 5 * autoLBVolume)

Example
autoLBVolume = 5000000
maxQueueSize =25MB

 

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...