Getting Data In

Loadbalancer or intermediate forwarder?

melonman
Motivator

Hi

I have many of universal forwarders that send (autoLB) events to multiple indexers in distributed search mode.
Now I am thinking to put 2 intermediate forwarders OR 2 load-balancers between universal forwarders and indexers.

Question:
Is it safe to use load-balancers between universal forwarders and indexers?
What is the best practice for this?

Thank you in advance..

0 Karma
1 Solution

esix_splunk
Splunk Employee
Splunk Employee

While you can use a load balancer between the UF and Indexers, why? The UF's have load balancing functionality built in via the outputs. Unless you are trying to redirect traffic to different indexers from specific ip/host ranges. That would be the only benefit.

Intermediate Forwarders are in best practices. They'll buffer if indexers or connections are down, and allow parsing / routing offloads in case of loads on indexers.

View solution in original post

esix_splunk
Splunk Employee
Splunk Employee

While you can use a load balancer between the UF and Indexers, why? The UF's have load balancing functionality built in via the outputs. Unless you are trying to redirect traffic to different indexers from specific ip/host ranges. That would be the only benefit.

Intermediate Forwarders are in best practices. They'll buffer if indexers or connections are down, and allow parsing / routing offloads in case of loads on indexers.

melonman
Motivator

Thank you!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...