Splunk Enterprise

useack in distributed environment 2 sets of heavy forwaders

craigwilkinson
Path Finder

Hi Splunk Support!

 

We currently have a large Distributed Envirionment where we have 3 sets of Heavy forwarders which have 2 nodes, before hitting an indexer.

Set HFWA --> Has 2 Heavy forwarders

Set HFWB --> has 2 heavy forwarders 

Set HFWC --> has 2 heavy forwarders

 

The data flow goes HFWA ---> HFWB ---> HFWC ---> Indexer.

 

HFWA outputs.conf has useACK=true.

HFWB & HFWC have useACK=false.

 

So

The data flow goes HFWA (useACK=true) ---> HFWB (useACK=false) ---> HFWC(useACK=false) ---> Indexer.

 

What is the expected output? Will HFWB Give an acknowledgement back to HFWA?

Is this an issue in our environment?

 

Thanks!

 

-Craig

 

 

Labels (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi
it’s exactly that way. You should use that same settings on all your uf + hf nodes to take it really into use. 
Did you know that your placement is not as Splunk’s best practices said. Optimal configuration is avoid HFS between UFs and indexers.

r. Ismo

0 Karma

craigwilkinson
Path Finder

Hi could you please explain by "its exactly that way"

If 2 sets of our heavy forwarders have useACK... but 1 of of the set of Heavy Forwarders doesnt have useACK before indexing.. what happens? Will the first 2 set of Heavy forwarders continue to hold the data until an ACK is recieved? Which I assume it enver will, because HFWC doesnt have this enabled?

0 Karma
Get Updates on the Splunk Community!

Celebrating Fast Lane: 2025 Authorized Learning Partner of the Year

At .conf25, Splunk proudly recognized Fast Lane as the 2025 Authorized Learning Partner of the Year. This ...

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...