Getting Data In

Events in a single file are not getting evenly distributed to multiple indexers

ishugupta
Path Finder

I have a light weight forwarder pointing two indexers . I get a batch data everyday in a single file . The file size is 28 GB on an average .
All the events in that file gets ingested in one single indexer . I noticed splunk is not able to distribute the events within a single file . It distributes events to indexers based on file level .So in case I get 10- 11 file on some day , one single file gets ingested to one single indexer and other file on other indexer. Is there any solution that can help me distribute the data on event level.
I am using Splunk 6.1.7

0 Karma

Runals
Motivator

I suspect what you are running into is a forwarder will send data to an indexer for 30s OR until it hits an end of file and then switch. If these are single files as part of a batch job I'm not surprised you are seeing the behavior you are describing. I'm not sure there is a good way to adjust that. You could check out the forceTimebasedAutoLB setting but I'm not sure this is the best use case for that setting.

ishugupta
Path Finder

thanks Runals , Seems like there is not concrete solution to this . I will have to break my files to multiple smaller files .
I do not want to change the forceTimebasedAutoLB setting , as it might truncate an event itself.

0 Karma

satishsdange
Builder

LWF is deprecated. Please replace it by UF.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...