Documentation: 3.0.2
Print Version Contents
This page last updated: 10/31/07 05:10pm

Set up data balancing

You can set up your forwarders to balance outputs by sending events in a round-robin fashion to separate Splunk servers. To set up data balancing, add a stanza to outputs.conf.

Configuration

Edit $SPLUNK_HOME/etc/bundles/local/outputs.conf:

[tcpout:FooGroup]
server=$IP:$PORT, $IP2:$PORT2, etc...

Specify the $IP:$PORT of the Splunk servers that will receive the forwarded data. You can enter any number of servers for Splunk to round-robin between. If one of the receiving servers goes down, the forwarder will send all events to the one that is still up, while simultaneously retrying the one that is down. If all servers are down, the forwarder will go into retry loops, and the queue will fill according to the queue configuration parameters.

Also, you can optionally specify back off and queue settings in outputs.conf. Please read about how to configure outputs.conf.

Example

[tcpout:SwanGroup]
server=10.1.1.197:9997, 10.1.1.200:9999

[tcpout:PearlGroup]
server=10.1.1.220:9997, 10.1.1.300:9999

With this configuration, Splunk will clone every event into 2 round-robin target groups.

Previous: Set up SSL    |    Next: Filtering and routing

Comments

No comments have been submitted.

Log in to comment.