Hello,
Here at my company we have one search head and three indexers.... We have a standalone server that has an Heavy Forwarder installed, we have a script on the server that is polling a database and sending the data to the forwarder through a TCP stream which gets indexed and forwarded to the indexers. The problem we are having is that the heavy forwarder is not properly distributing the data across the indexers and instead is sending everything to only one indexer... what should we do to solve this problem?
I believe that the problem is that it is a TCP stream. The autolb can't make the stream break. We see the same issue with routers sending data to a forwarder which load balances between 3 indexers. You will most likely notice that if you restart the splunk instance on the one indexer that is getting all the tcp stream data that it will change to the next one.
ivantn21, can you post your outputs.conf?
What would be the expected behavior?
I just edited the ouputs.conf to foward to three indexers and it does work for all sourcetypes it just don't load balance across the three indexers...
How did you set up load balancing ? Does load balancing work for other sourcetypes forwarded by the heavy forwarder ?