Getting Data In

Is it possible to weight splunk agents to prioritize specific indexers?

sonicZ
Contributor

I would like to weight certain indexers more then others as some of my indexers are older, and some are beefy new boxes.
Is there a way to weight indexer preference, perhaps in the outputs.conf server list?

0 Karma
1 Solution

kristian_kolb
Ultra Champion

No, you can't do that AFAIK. There is no such setting.

What you can do is to have half your forwarders to loadbalance between the new beefy indexers only, and the other half to loadbalance between all indexers. Adjust numbers to your environment.

Or if you can accomplish this through some third party loadbalancing product that has this functionality (i.e. configure forwarders to send to one address - the load balancer). This is not my area though, and I do not know any particular products that would support it.

Hope this helps,

Kristian

View solution in original post

0 Karma

kristian_kolb
Ultra Champion

No, you can't do that AFAIK. There is no such setting.

What you can do is to have half your forwarders to loadbalance between the new beefy indexers only, and the other half to loadbalance between all indexers. Adjust numbers to your environment.

Or if you can accomplish this through some third party loadbalancing product that has this functionality (i.e. configure forwarders to send to one address - the load balancer). This is not my area though, and I do not know any particular products that would support it.

Hope this helps,

Kristian

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...