Getting Data In

High availability setup - daily indexed volume

mikehibbert
New Member

We have a set-up where all of the forwarders send data to indexer A and indexer A forwards this on to indexer B, hence giving us a high (data query) availability solution.

What confuses me is that the indexed data on indexer B is double that on A... This doesn't seem to make sense to me, it should be identical?

Indexer B is also above the HA license quota, yet never violates. Obviously this is something to do with the HA license, but since I don't understand the mechanics of this thoroughly I'm not sure exactly why it doesn't violate.

Please could someone shed some light?!

0 Karma

Damien_Dallimor
Ultra Champion

What confuses me is that the indexed data on indexer B is double that on A

Perhaps as well as Indexer A cloning on to Indexer B your forwarders are also cloning to Indexer B ?? Just taking a guess in the dark, but something to check for anyway.

0 Karma

Drainy
Champion

hmm, it was my first thought to. Probably a good idea to double check the config on the forwarders in case someone has created a group and popped both indexers into it

0 Karma

mikehibbert
New Member

I don't think this is the case, as the solution document says agents will need to be reconfigured to "point" to the other indexer in case of failure... Good idea though!

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...