Splunk UF does the load balancing for based on frequency/time.
Does load balancing on UF works for file-based inputs as well? Or does that requires external HWF
Hi @dbhojani,
no, you don't need an external LB because for internal communications, Splunk has its own an auto load balancing mechanism, so an UF rotates the configurated destinations sending its logs.
An external LB is mandatory to have HA in syslog or HEC ingestions and to access the user front end having a Search Head Cluster.
Ciao.
Giuseppe
Thank you for confirmation.
Hi @dbhojani ,
if the answer solves your need, please accept it for the other people of Community or tell me how I can help you.
Ciao and happy splunking
Giuseppe
P.S.: Karma Points are appreciated 😉
Hi @dbhojani,
no, you don't need an external LB because for internal communications, Splunk has its own an auto load balancing mechanism, so an UF rotates the configurated destinations sending its logs.
An external LB is mandatory to have HA in syslog or HEC ingestions and to access the user front end having a Search Head Cluster.
Ciao.
Giuseppe