Getting Data In

Is it possible to enable useACK without sending cooked data?

acidkewpie
Path Finder

Hi,

Is it possible to enable useACK without sending cooked data?

If we have two independent splunk worlds, and I'm forwarding data from one to another, it seems illogical to send cooked data when the source types and indexes don't match up. But I need the assurance that useAck (allegedly) provides.

Tags (2)

dwaddle
SplunkTrust
SplunkTrust

If you aren't doing Splunk-to-Splunk protocol (that is, you are using a raw TCP socket), then useACK is not possible. The useACK feature is a part of the Splunk-to-Splunk forwarding protocol. In outputs.conf, the sendCookedData option seems to be setting whether the output is a raw socket or a splunk-to-splunk socket. So, I would say, "no, you cannot use useACK and send uncooked data"

bosburn_splunk
Splunk Employee
Splunk Employee

Can you clarify what your use case is?

All cooked data means is that it's data that's been sent from one Splunk instance to another - i.e. from a forwarder to an indexer, or an indexer to another indexer.

You can't useACK for items such as UDP input, tcp inputs, etc. since the originating machine wouldn't understand the acknowledgement.

Does that make sense?

Brian

acidkewpie
Path Finder

It does, but I've looked at the data on a useAck enabled connection and I don't see any actual data coming back, just an empty ACK from the indexer. If there's no actual protocol level conversation, I don't see what useACK is really doing, and if it's only on the ACK packet, what the reason for it not working with raw data would be.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Unlocking Unified Insights: New Gigamon Federated Search App for Splunk

In today’s data-heavy environment, organizations are caught in a data distribution dilemma. As data volumes ...

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...