Getting Data In

High availability setup - daily indexed volume

mikehibbert
New Member

We have a set-up where all of the forwarders send data to indexer A and indexer A forwards this on to indexer B, hence giving us a high (data query) availability solution.

What confuses me is that the indexed data on indexer B is double that on A... This doesn't seem to make sense to me, it should be identical?

Indexer B is also above the HA license quota, yet never violates. Obviously this is something to do with the HA license, but since I don't understand the mechanics of this thoroughly I'm not sure exactly why it doesn't violate.

Please could someone shed some light?!

0 Karma

Damien_Dallimor
Ultra Champion

What confuses me is that the indexed data on indexer B is double that on A

Perhaps as well as Indexer A cloning on to Indexer B your forwarders are also cloning to Indexer B ?? Just taking a guess in the dark, but something to check for anyway.

0 Karma

Drainy
Champion

hmm, it was my first thought to. Probably a good idea to double check the config on the forwarders in case someone has created a group and popped both indexers into it

0 Karma

mikehibbert
New Member

I don't think this is the case, as the solution document says agents will need to be reconfigured to "point" to the other indexer in case of failure... Good idea though!

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...