I am forwarding some logs from a Heavy Forwarder to 2 indexers. I want to check if forwarder is balancing load/distributing events properly or not ?
index = false
defaultGroup = G1
forwardedindex.filter.disable = true
disabled = 0
server = IP_Addr_Indexer1:9997,IP_Addr_Indexer2:9997
forceTimebasedAutoLB = true
autoLB = true
Like out of 100 events, say 40 events are going to indexer 1 and the rest 60 going to indexer 2. How can I check it ?
Run the query to check -
index=SomeIndex sourcetype=SomeSourcetype | timechart count by splunk_server
On which machine should I run this query - Indexer or SH ? And what should be the output of this query ?