Getting Data In

How do load-balanced forwarders select receivers?

isaacvb
Explorer

The Splunk docs for Forwarder load-balancing say that a forwarder randomly chooses between the different available receivers when it has to change where it's sending data.

What are the specifics of this change?
Can the forwarder select the same indexer again?
Does the forwarder guarantee cycling through all the indexers by reducing its available switching pool each time until it's sent data to all of them, or is it possible for a forwarder to switch between only a few indexers out of the ones available e.g. A B A B out of A B C?

My basic guess was that it just picked any indexer that wasn't the one it was sending to at that moment, but it didn't seem that clear.

0 Karma
1 Solution

renjith_nair
Legend

Normally forwarder switches at every regular interval, say 30 mins or if the indexer goes down
The selection of receiver from the group is random
If you want to select only two out of three, you can configure that.

Detailed doc available here : http://docs.splunk.com/Documentation/Splunk/6.2.0/Forwarding/Setuploadbalancingd

On top of this, If you have a specific issue, then somebody might be able to help you

---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

0 Karma

renjith_nair
Legend

Normally forwarder switches at every regular interval, say 30 mins or if the indexer goes down
The selection of receiver from the group is random
If you want to select only two out of three, you can configure that.

Detailed doc available here : http://docs.splunk.com/Documentation/Splunk/6.2.0/Forwarding/Setuploadbalancingd

On top of this, If you have a specific issue, then somebody might be able to help you

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...