Getting Data In

How do load-balanced forwarders select receivers?

isaacvb
Explorer

The Splunk docs for Forwarder load-balancing say that a forwarder randomly chooses between the different available receivers when it has to change where it's sending data.

What are the specifics of this change?
Can the forwarder select the same indexer again?
Does the forwarder guarantee cycling through all the indexers by reducing its available switching pool each time until it's sent data to all of them, or is it possible for a forwarder to switch between only a few indexers out of the ones available e.g. A B A B out of A B C?

My basic guess was that it just picked any indexer that wasn't the one it was sending to at that moment, but it didn't seem that clear.

0 Karma
1 Solution

renjith_nair
Legend

Normally forwarder switches at every regular interval, say 30 mins or if the indexer goes down
The selection of receiver from the group is random
If you want to select only two out of three, you can configure that.

Detailed doc available here : http://docs.splunk.com/Documentation/Splunk/6.2.0/Forwarding/Setuploadbalancingd

On top of this, If you have a specific issue, then somebody might be able to help you

---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

0 Karma

renjith_nair
Legend

Normally forwarder switches at every regular interval, say 30 mins or if the indexer goes down
The selection of receiver from the group is random
If you want to select only two out of three, you can configure that.

Detailed doc available here : http://docs.splunk.com/Documentation/Splunk/6.2.0/Forwarding/Setuploadbalancingd

On top of this, If you have a specific issue, then somebody might be able to help you

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...