Dear Experts,
We are currently using Splunk 6.0.1 in a clustered environment.
We have our forwarders streaming data to 2 indexers.
One of our indexers, the server has a hardware issue and therefore the indexer is not working properly.
The other indexer is working fine.
How do I have my forwarders redirect all their data to that specific indexer that is working?
Any advice is very much appreciated.
Thanks,
As per the documentation, "If one receiver goes down, the forwarder automatically switches to another one on the list. ". It means stopping the Indexer which is not working properly should be sufficient to redirect all data to working Indexer.
Use load balancing on forwarders.
Read How Load Balancing Works in http://docs.splunk.com/Documentation/Splunk/6.1.2/Indexer/Useforwarderstogetyourdata
And, this http://docs.splunk.com/Documentation/Splunk/6.1.2/Forwarding/Setuploadbalancingd