Getting Data In

indexers having very different volume usage

inanX
Engager

Hi,

We have a single pool with two indexers. The indexers switch every 30 minutes so it is generally expected that they would have almost similar values of volume usage.

Now i can figure out why the first indexer is 21GB and the other is 28GB.

I hope someone can help. Thanks in advanced. 🙂

Yours,

Ferdinand

Tags (3)
1 Solution

jbsplunk
Splunk Employee
Splunk Employee

I would suggest taking a look at the searches here:

http://wiki.splunk.com/Community:TroubleshootingIndexedDataVolume

Specifically, Quick summary information by host, source, sourcetype and index to locate the cause of the variance.

I presume that you are using auto load balancing on a forwarder, although you have stated that is the case. The sessions are not going to send exactly the same amount of data. It really depends on the type of data being sent. For instance, udp packets are going to be essentially one event per packet. Windows Event logs are not going to be one event per packet because of the way that Splunk uses WQL to query for events. You end up with variations in the size of the data sent to each indexer under that type of a configuration.

View solution in original post

jbsplunk
Splunk Employee
Splunk Employee

I would suggest taking a look at the searches here:

http://wiki.splunk.com/Community:TroubleshootingIndexedDataVolume

Specifically, Quick summary information by host, source, sourcetype and index to locate the cause of the variance.

I presume that you are using auto load balancing on a forwarder, although you have stated that is the case. The sessions are not going to send exactly the same amount of data. It really depends on the type of data being sent. For instance, udp packets are going to be essentially one event per packet. Windows Event logs are not going to be one event per packet because of the way that Splunk uses WQL to query for events. You end up with variations in the size of the data sent to each indexer under that type of a configuration.

Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...