Splunk Enterprise

Setting useACK in outputs.conf in a Distributed Environment (Universal Forwarder + Heavy Forwarder + Indexer)

edoardo_vicendo
Builder

Hello,

In a distributed environment with Universal Forwarder, Heavy Forwarder and Indexers, like this one:

UF --> HF --> IDX

How do you set useACK=true in outputs.conf ?

Is it needed to be enabled both on Universal Forwarder and Heavy Forwarder?

We currently have it enabled only on the Heavy Forwarder.

Thanks a lot,

Edoardo

Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

As I understand it, the instance with useACK=true will buffer packets until they are acknowledged by the indexer.  If useACK=false then the packet is discarded once it is sent.  (These are Splunk packets, not TCP packets.)  Also, useACK adds a kind of flow control to the data stream.  For better end-to-end control, use useACK=true on the UF and HF.  Note that this will force the instance to use more memory.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

As I understand it, the instance with useACK=true will buffer packets until they are acknowledged by the indexer.  If useACK=false then the packet is discarded once it is sent.  (These are Splunk packets, not TCP packets.)  Also, useACK adds a kind of flow control to the data stream.  For better end-to-end control, use useACK=true on the UF and HF.  Note that this will force the instance to use more memory.

---
If this reply helps you, Karma would be appreciated.

edoardo_vicendo
Builder
0 Karma
Get Updates on the Splunk Community!

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Automatic Discovery Part 2: Setup and Best Practices

In Part 1 of this series, we covered what Automatic Discovery is and why it’s critical for observability at ...