Getting Data In

what happens to the data forwarded to indexer when the index is not present ?

splunker12er
Motivator

Sample Warning Message:

Search peer 10.0.1.1 has the following message: received event for unconfigured/disabled/deleted index='Index-A' with source='10.3.0.97.log' host='host::device1' sourcetype='sourcetype::cisco' (1 missing total)
  • conditions:

out if 4 indexers , 2 indexers alone have "Index-A" index,. where the other 2 indexers do not have that index.
My splunk forwarder (heavy) is set to auto_lb to all the 4 indexers.

  • queries:

In this case, whether the data sent from splunk forwarder to those indexers will be lost ? - For sure this wont happen(I assume , as TCP doesn't send ack , no data transfer further - am i right here?!)

or since splunkd doesn't accept the data , as the index is not present , the data is bounced back to the other indexers ? auto_lb ? How do splunk handle this?

please advise.

0 Karma
1 Solution

MuS
Legend

Hi splunk12er,

if the events hit an indexer where the index is not present, it will not be stored (it is lost in your words) and the message is shown. Splunk will not bounce it back to any other indexer.
You have to take care that each index which is defined in your inputs, is available on each indexers if you're using auto-lb or setup the UF to only forward to the two indexers which hold the index.

Hope this helps ...

cheers, MuS

View solution in original post

0 Karma

MuS
Legend

Hi splunk12er,

if the events hit an indexer where the index is not present, it will not be stored (it is lost in your words) and the message is shown. Splunk will not bounce it back to any other indexer.
You have to take care that each index which is defined in your inputs, is available on each indexers if you're using auto-lb or setup the UF to only forward to the two indexers which hold the index.

Hope this helps ...

cheers, MuS

0 Karma

splunker12er
Motivator

Thanks. this information is helpful.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...