Getting Data In

it's possible balnce an hec source?

aasabatini
Motivator

Hi Folks,

 

I have a question, I have 2 HF and I have to configure a hec source, I would balance the data across the two HF.

do you know the best pratices to do this?

Do i have to create the same inputs with the same token on both the HF and use a load balancer to do that?

 

Thanks in advance

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”
Labels (1)
0 Karma
1 Solution

PickleRick
SplunkTrust
SplunkTrust

Yes, that's exactly how you do it. You create a HEC input with the same settings (token, destination index/permitted indexes, maybe TLS settings if you're not offloading it to your LB). And you just place your LB in front of those HECs. Works like a charm 🙂

View solution in original post

PickleRick
SplunkTrust
SplunkTrust

Yes, that's exactly how you do it. You create a HEC input with the same settings (token, destination index/permitted indexes, maybe TLS settings if you're not offloading it to your LB). And you just place your LB in front of those HECs. Works like a charm 🙂

aasabatini
Motivator

Hi @PickleRick z, @gcusello ,

 

thanks for your confimation guys, just last question, do you know or exist some official documentation  about that? I mean the load balacing across the hec, no generic documentation.

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”
0 Karma

PickleRick
SplunkTrust
SplunkTrust

I'm not sure there is any as such. This is more about HTTP in general, it's not specific to HEC as such. It's exactly the same as with any load-balanced service. You probably can find some .conf presentation mentioning it or something or event training materials but I don't think it _needs_ a specific official documentation. HTTP is generally proxable so there is no reason why HEC shouldn't.

0 Karma

aasabatini
Motivator

Thanks @PickleRick 

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”
0 Karma

gcusello
SplunkTrust
SplunkTrust

Ciao Alessandro,

yes, it's always better to use a Load Balancer to ingest syslogs: to distribute load during normal work and manage unavailability on one of them during fail over.

If you haven't a Load Balancer (always the best solution!) you could also use a DNS configuration, but it isn't so affidable because it takes some time to understand when an HF isn't available, so it looses some syslogs.

Then you configure on both the HFs the input with the same token.

Ciao.

Giuseppe

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

Federated Search for Dynamic Data Self Storage Is Now Generally Available on Splunk ...

 Splunk is excited to announce the General Availability of Federated Search for Dynamic Data Self Storage ...

Index This | What has many keys but can’t unlock a door?

July 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...