Splunk Search

UF sending data in LB fashion

nikhilmehra79
Path Finder

I have following config in my output.conf

[tcpout]
defaultGroup = productionSplunk1, productionSplunk2

[tcpout:productionSplunk1]
server = X.X.X.X:9997

[tcpout:productionSplunk2]

server = Y.Y.Y.Y:9997

I have search head and 2 indexers (x.x.x.x) and (y.y.y.y), when i now look in search head i am gettign double events , eg say UF send 2 events, i am getting 4 at search head - 2 from each of above indexers.

I expected the UF to send data to me in LB fashioned. Which is what it is not doing, any idea what is bad with my config

0 Karma

HiroshiSatoh
Champion

It is my config file. 1 minute at intervals will then load balance.

my output.conf
[tcpout]
defaultGroup = LB_indexers

[tcpout:LB_indexers]
disabled = false
autoLBFrequency = 60
server = x.x.x.x:9997,y.y.y.y:9997

HiroshiSatoh
Champion
0 Karma

nikhilmehra79
Path Finder

Do you really need?

[tcpout] defaultGroup = LB_indexers

0 Karma

nikhilmehra79
Path Finder

i am trying now this - does this look fine?
[tcpout:my_LB_indexers]
server=X.X.X.X:9997,Y.Y.Y.Y:9997

0 Karma

nikhilmehra79
Path Finder

Thanks , qq - what is significance of 1 minute - does it tell UF to send data 1 minute apart ?

0 Karma
Get Updates on the Splunk Community!

Fueling your curiosity with new Splunk ILT and eLearning courses

At Splunk Education, we’re driven by curiosity—both ours and yours! That’s why we’re committed to delivering ...

Splunk AI Assistant for SPL 1.1.0 | Now Personalized to Your Environment for Greater ...

Splunk AI Assistant for SPL has transformed how users interact with Splunk, making it easier than ever to ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureOn Demand Now Step boldly into the AI revolution with enhanced security ...