All Apps and Add-ons

REST API Modular input app and Distributed deployment

be910j
Path Finder

Curious if anyone has found a good way to deal with this issue.

I currently have a distributed deployment with 6 active Indexers. Currently testing the REST API Modular Input app on a single instance test box and its working great but I want to move it over to my prod environment now and put it into our distributed model.
With just the polling model and no cron option (that I saw) is there a way I can keep the data distributed across my multi indexers easily or is it more along the lines of using a single box to make the initial grab/index and forward that data over to my indexer farm for distribution, or maybe setting the polling time on each indexer in such a way that they won't overlap, though Im not sure what kind of combination that would be and would prob grow to be quite complex I would assume?Heavy forwarder and a dedicated API Collection server- VM maybe? Just wandering if there was a preferred method or what people have found success with.

Cheers,
Brandon

1 Solution

be910j
Path Finder

Well just to post a follow up here, while I'm not positive if it's the best way, I ended up building a heavy forwarder to do all the work and send the cooked data over to my indexers, so far seems to be working ok.

-brandon

View solution in original post

Damien_Dallimor
Ultra Champion

There's no distributed co-ordination logic in the REST API Modular Input , so they way you have approached it is probably the best option.

0 Karma

be910j
Path Finder

Well just to post a follow up here, while I'm not positive if it's the best way, I ended up building a heavy forwarder to do all the work and send the cooked data over to my indexers, so far seems to be working ok.

-brandon

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...