Getting Data In

High availability setup - daily indexed volume

mikehibbert
New Member

We have a set-up where all of the forwarders send data to indexer A and indexer A forwards this on to indexer B, hence giving us a high (data query) availability solution.

What confuses me is that the indexed data on indexer B is double that on A... This doesn't seem to make sense to me, it should be identical?

Indexer B is also above the HA license quota, yet never violates. Obviously this is something to do with the HA license, but since I don't understand the mechanics of this thoroughly I'm not sure exactly why it doesn't violate.

Please could someone shed some light?!

0 Karma

Damien_Dallimor
Ultra Champion

What confuses me is that the indexed data on indexer B is double that on A

Perhaps as well as Indexer A cloning on to Indexer B your forwarders are also cloning to Indexer B ?? Just taking a guess in the dark, but something to check for anyway.

0 Karma

Drainy
Champion

hmm, it was my first thought to. Probably a good idea to double check the config on the forwarders in case someone has created a group and popped both indexers into it

0 Karma

mikehibbert
New Member

I don't think this is the case, as the solution document says agents will need to be reconfigured to "point" to the other indexer in case of failure... Good idea though!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Drivers: How We're Streaming Real-Time F1 Telemetry Directly into Splunk ...

Data Drivers: Every Lap Tells a Story The Spectacle Two F1 racing sims go head-to-head on the .conf26 show ...

Data Management Digest – July 2026

  Welcome to the July 2026 edition of Data Management Digest! As your trusted partner in data innovation, the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...