I have following config in my output.conf
defaultGroup = productionSplunk1, productionSplunk2
server = X.X.X.X:9997
server = Y.Y.Y.Y:9997
I have search head and 2 indexers (x.x.x.x) and (y.y.y.y), when i now look in search head i am gettign double events , eg say UF send 2 events, i am getting 4 at search head - 2 from each of above indexers.
I expected the UF to send data to me in LB fashioned. Which is what it is not doing, any idea what is bad with my config
It is my config file. 1 minute at intervals will then load balance.
defaultGroup = LB_indexers
[tcpout:LB_indexers] disabled = false autoLBFrequency = 60 server = x.x.x.x:9997,y.y.y.y:9997
I was referring to this URL.
I think whether this serves as a reference.