Splunk Enterprise

how to enable tcp data input in index cluster and how to configure client to forward the data?

sbhaskaran
Explorer

I have a indexer cluster and When I enable tcp data input

How can I ask Master to receive the input?
right now in client conf I am specifying one indexer ip:port but I don't see any replication for the data received.

Any help will be appreciated.

Tags (1)
0 Karma

jwelch_splunk
Splunk Employee
Splunk Employee

repFactor = |auto
* Only relevant if this instance is a clustering slave (but see note about
"auto" below).
* See server.conf spec for details on clustering configuration.
* Value of 0 turns off replication for this index.
* If set to "auto", slave will use whatever value the master has.
* Highest legal value is 4294967295
* Defaults to 0.

Indexes.conf.spec

0 Karma

sbhaskaran
Explorer

@jwelch thanks for answering. repFactor = |auto helps to replicate the index. but still on client I am not able to specify the master host/port so it will send the data to master and it internally load balance it.

0 Karma
Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...