All Apps and Add-ons

How to load balance between the indexers for Outcold and Monitoring Kubernetes collector setup to ingest data?

sathwikr076
Communicator

@outcoldman, we are using Monitoring Kubernetes App and Outcold collector Setup to ingest the data, but is there any way to have load balancing between the indexers, because right now, the servers ingest to only one indexer using random-with-round-robin - choose random URL on first selection and after that in round-robin on each failure.

Thanks.

0 Karma
1 Solution

outcoldman
Communicator

@sathwikr076 there are several options:

  1. Setup a Load Balancer in front of your indexers. See http://dev.splunk.com/view/event-collector/SP-CAAAE73
  2. You can specify multiple HTTP Event Collector endpoints with the collectord. https://www.outcoldsolutions.com/docs/monitoring-kubernetes/v5/splunk-output/#using-multiple-http-ev... Every instance of collectord will choose randomly one from the list.

View solution in original post

0 Karma

outcoldman
Communicator

@sathwikr076 there are several options:

  1. Setup a Load Balancer in front of your indexers. See http://dev.splunk.com/view/event-collector/SP-CAAAE73
  2. You can specify multiple HTTP Event Collector endpoints with the collectord. https://www.outcoldsolutions.com/docs/monitoring-kubernetes/v5/splunk-output/#using-multiple-http-ev... Every instance of collectord will choose randomly one from the list.
0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...