Splunk Enterprise

Load Balancing in UF doesn`t work

sh_tavousi
Explorer

Hi,

I have 2 indexers and I have set them in outputs.conf but my logs are indexed in one of them. I guess load balancing doesn`t work well. I want to know how I can know if load balancing works well as one of my indexers is going full but another is not. We have 2 clustered indexers.

Thanks.

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Load balancing in UF *does* work and works quite well, if you do it right.  Have you read https://docs.splunk.com/Documentation/Forwarder/8.1.3/Forwarder/Configureloadbalancing ?  Pay particular attention to the section "Props.conf settings to improve distribution of data in load balancing" because your data can affect how load balancing behaves.

---
If this reply helps you, Karma would be appreciated.
0 Karma

sh_tavousi
Explorer

Hi,

If we set our 2 indexers in outputs.conf of  UFs ,according to the link you sent, UFs send logs to one of them until EOF. Therefore one of our indexers receives logs and by replication, logs will replicate between them. 

Is it true?

As We have 2 indexers and they are clustered I want to know if replication  between them is done properly.

Thanks.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

A UF will send data to one indexer until a trigger causes it to switch to a different indexer.  That trigger can be time (30 seconds, by default), volume (off, by default), EOF (IIRC), or a lost indexer connection.

Yes, clustered indexers will replicate data among themselves per the replication factor (RF) setting.  I'm not sure what you mean by "properly", however.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...