Getting Data In

Peer sends acknowledgment whether fulfil replication factor when forwarder is mAck=true

Wenjian_Zhu
Explorer

Dear splunkers,

When set useAck = true (https://docs.splunk.com/Documentation/Splunk/9.4.0/Forwarding/Protectagainstlossofin-flightdata).

The source peer sends acknowledgment after writing the data to its file system and ensuring the replication factor is met 

or

The source peer sends acknowledgment after writing the data to its file system.

 

Best regards,

Labels (2)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Actually it needs that replication factor has met on indexers before the ack has sent.

You should read below post and also those where are linked there.


Here is one old excellent post about it https://community.splunk.com/t5/Knowledge-Management/Splunk-Indexer-Forwarder-Acknowledgement-explai...

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

Actually it needs that replication factor has met on indexers before the ack has sent.

You should read below post and also those where are linked there.


Here is one old excellent post about it https://community.splunk.com/t5/Knowledge-Management/Splunk-Indexer-Forwarder-Acknowledgement-explai...

Wenjian_Zhu
Explorer

Hi @isoutamo ,

Thx a lot 👍.

BR

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @Wenjian_Zhu 

 Indexer acknowledgment will be sent after data written into the disk of indexer. 

there is no relation with data replication with indexer acknowledgment

acknowledgment is to let forwarders know data has been received at the indexer end and forwarder which sent data to indexer , will remove the events from the wait queue.

also recommended to enable   acknowledgment at at intermediate forwader and indexer 

SanjayReddy_0-1738418106233.png

 

Wenjian_Zhu
Explorer

Hi @SanjayReddy 

Thanks for the feedback, that screenshot is when receiver is a forwarder.

This is a good explanation https://community.splunk.com/t5/Knowledge-Management/Splunk-Indexer-Forwarder-Acknowledgement-explai... as @isoutamo mentioned.

Thanks. 

0 Karma
Get Updates on the Splunk Community!

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...

AppDynamics is now part of Splunk Ideas

Hello Splunkers, We have exciting news for you! AppDynamics has been added to the Splunk Ideas Portal. Which ...

Advanced Splunk Data Management Strategies

Join us on Wednesday, May 14, 2025, at 11 AM PDT / 2 PM EDT for an exclusive Tech Talk that delves into ...