Splunk Enterprise

Load Balancing in UF doesn`t work

sh_tavousi
Explorer

Hi,

I have 2 indexers and I have set them in outputs.conf but my logs are indexed in one of them. I guess load balancing doesn`t work well. I want to know how I can know if load balancing works well as one of my indexers is going full but another is not. We have 2 clustered indexers.

Thanks.

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Load balancing in UF *does* work and works quite well, if you do it right.  Have you read https://docs.splunk.com/Documentation/Forwarder/8.1.3/Forwarder/Configureloadbalancing ?  Pay particular attention to the section "Props.conf settings to improve distribution of data in load balancing" because your data can affect how load balancing behaves.

---
If this reply helps you, Karma would be appreciated.
0 Karma

sh_tavousi
Explorer

Hi,

If we set our 2 indexers in outputs.conf of  UFs ,according to the link you sent, UFs send logs to one of them until EOF. Therefore one of our indexers receives logs and by replication, logs will replicate between them. 

Is it true?

As We have 2 indexers and they are clustered I want to know if replication  between them is done properly.

Thanks.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

A UF will send data to one indexer until a trigger causes it to switch to a different indexer.  That trigger can be time (30 seconds, by default), volume (off, by default), EOF (IIRC), or a lost indexer connection.

Yes, clustered indexers will replicate data among themselves per the replication factor (RF) setting.  I'm not sure what you mean by "properly", however.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...