Sample Warning Message:
Search peer 10.0.1.1 has the following message: received event for unconfigured/disabled/deleted index='Index-A' with source='10.3.0.97.log' host='host::device1' sourcetype='sourcetype::cisco' (1 missing total)
out if 4 indexers , 2 indexers alone have "Index-A" index,. where the other 2 indexers do not have that index.
My splunk forwarder (heavy) is set to auto_lb to all the 4 indexers.
In this case, whether the data sent from splunk forwarder to those indexers will be lost ? - For sure this wont happen(I assume , as TCP doesn't send ack , no data transfer further - am i right here?!)
or since splunkd doesn't accept the data , as the index is not present , the data is bounced back to the other indexers ? auto_lb ? How do splunk handle this?
please advise.
Hi splunk12er,
if the events hit an indexer where the index is not present, it will not be stored (it is lost in your words) and the message is shown. Splunk will not bounce it back to any other indexer.
You have to take care that each index which is defined in your inputs, is available on each indexers if you're using auto-lb or setup the UF to only forward to the two indexers which hold the index.
Hope this helps ...
cheers, MuS
Hi splunk12er,
if the events hit an indexer where the index is not present, it will not be stored (it is lost in your words) and the message is shown. Splunk will not bounce it back to any other indexer.
You have to take care that each index which is defined in your inputs, is available on each indexers if you're using auto-lb or setup the UF to only forward to the two indexers which hold the index.
Hope this helps ...
cheers, MuS
Thanks. this information is helpful.