Getting Data In

what happens to the data forwarded to indexer when the index is not present ?

splunker12er
Motivator

Sample Warning Message:

Search peer 10.0.1.1 has the following message: received event for unconfigured/disabled/deleted index='Index-A' with source='10.3.0.97.log' host='host::device1' sourcetype='sourcetype::cisco' (1 missing total)
  • conditions:

out if 4 indexers , 2 indexers alone have "Index-A" index,. where the other 2 indexers do not have that index.
My splunk forwarder (heavy) is set to auto_lb to all the 4 indexers.

  • queries:

In this case, whether the data sent from splunk forwarder to those indexers will be lost ? - For sure this wont happen(I assume , as TCP doesn't send ack , no data transfer further - am i right here?!)

or since splunkd doesn't accept the data , as the index is not present , the data is bounced back to the other indexers ? auto_lb ? How do splunk handle this?

please advise.

0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi splunk12er,

if the events hit an indexer where the index is not present, it will not be stored (it is lost in your words) and the message is shown. Splunk will not bounce it back to any other indexer.
You have to take care that each index which is defined in your inputs, is available on each indexers if you're using auto-lb or setup the UF to only forward to the two indexers which hold the index.

Hope this helps ...

cheers, MuS

View solution in original post

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi splunk12er,

if the events hit an indexer where the index is not present, it will not be stored (it is lost in your words) and the message is shown. Splunk will not bounce it back to any other indexer.
You have to take care that each index which is defined in your inputs, is available on each indexers if you're using auto-lb or setup the UF to only forward to the two indexers which hold the index.

Hope this helps ...

cheers, MuS

0 Karma

splunker12er
Motivator

Thanks. this information is helpful.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...