Hi,
We are setting up splunk in AWS and we currently have a cluster with 1 Master, 3 indexers, 1 deployer, 3 searchheads(includes 1 captain).
We do not use any forwarders and so enabled HEC in indexers. Now we are trying to setup a load balancer in front of indexers to send the data to be indexed.
Do we have any recommended way to configure this ELB of rindexers with HEC and no forwarders in AWS?
Below are few more questions I have
Any help is highly appreciated
If you are using indexer discovery, as you should be with an indexer cluster and master, there is not really any benefit to load balancing the indexers. The master will handle that for you. There are two methods, time based and volume based. The prior is likely best (every 30 seconds, etc. as opposed to every 10mb e.g.).
Enabling HEC on indexers directly is not good practice, imvho. Those should be dedicated nodes.
https://docs.splunk.com/Documentation/Splunk/8.0.2/Forwarding/Setuploadbalancingd