Getting Data In

Load Balancing without the use of Forwarders

Ant1D
Motivator

Hi,

I have set up a Splunk environment in which several applications will be sending data to a collection of indexers. I am considering using a traditional load balancer to manage the receiving of data by the indexers. Is this possible with a traditional load balancer or can I only do load balancing in Splunk via a Forwarder's load balancing capabilities?

Thanks in advance for your replies.

0 Karma

bmacias84
Champion

@Ant1D, The anwser is yes you can. To accomplish this you would use a modified version of Horizontal Scaling. Once you have configured you Traditional LB just configure your autoLBFrequency to the desireved value which will cause the forward to start a new stream on that interval.

Additional reading:


[tcpout]
defaultGroup=my_traditionalLB
[tcpout:my_traditionalLB]
disabled=false
autoLBFrequency=40
server=<IPorFQDN_of_LB>:9997

Hope this help or gets you started. Dont forget to vote or accept answers.

Cheers,

Ant1D
Motivator

An example of a traditional load balancer here would be Cisco ACE

0 Karma

Ant1D
Motivator

Hi I am basically saying that I do not want to use the load balancing functionality on Splunk Forwarders. I essentially want to know if someone has used an alternative to manage how data is sent to collection of forwarders

0 Karma

barakreeves
Splunk Employee
Splunk Employee

To better help you, could you please define what a "traditional load balancer" is? Then we should be able to help you out.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...