Getting Data In

Does Splunk recommend not to use a load balancer between a forwarder and indexer?

AzmathShaik
Path Finder

Hello

i was trying to implement a load balancer in between a forwarder and indexer. but i somehow remember that Splunk doesn't recommend this option. is there any statement provided in documentation?

if any one points to that would be really helpful.

Thanks

0 Karma
1 Solution

somesoni2
Revered Legend

See the note at the end of para 1 here.

https://docs.splunk.com/Documentation/Forwarder/6.5.2/Forwarder/Configureloadbalancing

Note: You should not use an external load balancer to implement load balancing between forwarders and receivers. This practice does not generate the results you would expect. Use the load balancing capability that comes with the forwarder.

View solution in original post

somesoni2
Revered Legend

See the note at the end of para 1 here.

https://docs.splunk.com/Documentation/Forwarder/6.5.2/Forwarder/Configureloadbalancing

Note: You should not use an external load balancer to implement load balancing between forwarders and receivers. This practice does not generate the results you would expect. Use the load balancing capability that comes with the forwarder.

bhavikbhalodia
Path Finder

Can you please explain what does below sentence represent?
This practice does not generate the results you would expect.

0 Karma

AzmathShaik
Path Finder

Thanks it really helped me. i missed the note when i was referring the this document.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...