Getting Data In

what happens to the data forwarded to indexer when the index is not present ?

splunker12er
Motivator

Sample Warning Message:

Search peer 10.0.1.1 has the following message: received event for unconfigured/disabled/deleted index='Index-A' with source='10.3.0.97.log' host='host::device1' sourcetype='sourcetype::cisco' (1 missing total)
  • conditions:

out if 4 indexers , 2 indexers alone have "Index-A" index,. where the other 2 indexers do not have that index.
My splunk forwarder (heavy) is set to auto_lb to all the 4 indexers.

  • queries:

In this case, whether the data sent from splunk forwarder to those indexers will be lost ? - For sure this wont happen(I assume , as TCP doesn't send ack , no data transfer further - am i right here?!)

or since splunkd doesn't accept the data , as the index is not present , the data is bounced back to the other indexers ? auto_lb ? How do splunk handle this?

please advise.

0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi splunk12er,

if the events hit an indexer where the index is not present, it will not be stored (it is lost in your words) and the message is shown. Splunk will not bounce it back to any other indexer.
You have to take care that each index which is defined in your inputs, is available on each indexers if you're using auto-lb or setup the UF to only forward to the two indexers which hold the index.

Hope this helps ...

cheers, MuS

View solution in original post

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi splunk12er,

if the events hit an indexer where the index is not present, it will not be stored (it is lost in your words) and the message is shown. Splunk will not bounce it back to any other indexer.
You have to take care that each index which is defined in your inputs, is available on each indexers if you're using auto-lb or setup the UF to only forward to the two indexers which hold the index.

Hope this helps ...

cheers, MuS

0 Karma

splunker12er
Motivator

Thanks. this information is helpful.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...