Getting Data In

Can we have fewer Heavy Forwarders than Indexers?

hrawat
Splunk Employee
Splunk Employee
 
Labels (1)
0 Karma
1 Solution

hrawat
Splunk Employee
Splunk Employee
 
 
Current practice is to have more Heavy Forwarders than Indexers to keep all indexers busy. However starting 7.3.6 onwards you don't have to. Heavy forwarder can send data to multiple indexers in parallel per ingest pipeline.

 

All you have to set in outputs.conf (maxQueueSize = 5 * autoLBVolume)

Example
autoLBVolume = 5000000
maxQueueSize =25MB

 

View solution in original post

hrawat
Splunk Employee
Splunk Employee
 
 
Current practice is to have more Heavy Forwarders than Indexers to keep all indexers busy. However starting 7.3.6 onwards you don't have to. Heavy forwarder can send data to multiple indexers in parallel per ingest pipeline.

 

All you have to set in outputs.conf (maxQueueSize = 5 * autoLBVolume)

Example
autoLBVolume = 5000000
maxQueueSize =25MB

 

Get Updates on the Splunk Community!

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...