Getting Data In

Peer sends acknowledgment whether fulfil replication factor when forwarder is mAck=true

Wenjian_Zhu
Explorer

Dear splunkers,

When set useAck = true (https://docs.splunk.com/Documentation/Splunk/9.4.0/Forwarding/Protectagainstlossofin-flightdata).

The source peer sends acknowledgment after writing the data to its file system and ensuring the replication factor is met 

or

The source peer sends acknowledgment after writing the data to its file system.

 

Best regards,

Labels (2)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Actually it needs that replication factor has met on indexers before the ack has sent.

You should read below post and also those where are linked there.


Here is one old excellent post about it https://community.splunk.com/t5/Knowledge-Management/Splunk-Indexer-Forwarder-Acknowledgement-explai...

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

Actually it needs that replication factor has met on indexers before the ack has sent.

You should read below post and also those where are linked there.


Here is one old excellent post about it https://community.splunk.com/t5/Knowledge-Management/Splunk-Indexer-Forwarder-Acknowledgement-explai...

Wenjian_Zhu
Explorer

Hi @isoutamo ,

Thx a lot 👍.

BR

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @Wenjian_Zhu 

 Indexer acknowledgment will be sent after data written into the disk of indexer. 

there is no relation with data replication with indexer acknowledgment

acknowledgment is to let forwarders know data has been received at the indexer end and forwarder which sent data to indexer , will remove the events from the wait queue.

also recommended to enable   acknowledgment at at intermediate forwader and indexer 

SanjayReddy_0-1738418106233.png

 

Wenjian_Zhu
Explorer

Hi @SanjayReddy 

Thanks for the feedback, that screenshot is when receiver is a forwarder.

This is a good explanation https://community.splunk.com/t5/Knowledge-Management/Splunk-Indexer-Forwarder-Acknowledgement-explai... as @isoutamo mentioned.

Thanks. 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...