Installation

License impact using load balancing

splunkreal
Motivator

Hello,

we have clustered indexers.

Could you confirm if the license usage is the same using these settings in the outputs.conf of universal forwarders :

[tcpout]
defaultGroup=indexer1,indexer2

[tcpout:indexer1]
server=10.1.1.197:9997

[tcpout:indexer2]
server=10.1.1.200:9997

I also noted it's possible to use this, however it may increase replication between indexers?

[tcpout:my_LB_indexers]
server=10.10.10.1:9997,10.10.10.2:9996,10.10.10.3:9995

Thanks a lot.

* If this helps, please upvote or accept solution if it solved *
Labels (3)
0 Karma
1 Solution

adonio
Ultra Champion

Why will it effect licensing?
License counts against data indexed in the indexers and ... that's it!
it does not count against replication, internal data etc.
read more here:
https://docs.splunk.com/Documentation/Splunk/6.6.0/InheritedDeployment/Licensing
and here:
http://docs.splunk.com/Documentation/Splunk/6.6.0/Admin/TypesofSplunklicenses
why will this configuration increase replication on indexers?
read more about outputs and forwarders load balancing here:
http://docs.splunk.com/Documentation/Forwarder/6.6.0/Forwarder/Configureforwardingwithoutputs.conf
hope it helps

View solution in original post

adonio
Ultra Champion

Why will it effect licensing?
License counts against data indexed in the indexers and ... that's it!
it does not count against replication, internal data etc.
read more here:
https://docs.splunk.com/Documentation/Splunk/6.6.0/InheritedDeployment/Licensing
and here:
http://docs.splunk.com/Documentation/Splunk/6.6.0/Admin/TypesofSplunklicenses
why will this configuration increase replication on indexers?
read more about outputs and forwarders load balancing here:
http://docs.splunk.com/Documentation/Forwarder/6.6.0/Forwarder/Configureforwardingwithoutputs.conf
hope it helps

Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...