Hi, i have a similar problem... at first my config to forward internal splunk indexes... [tcpout] forwardedindex.0.whitelist = _.* forwardedindex.filter.disable = false defaultGroup = TEST_IDX-CLUSTER [tcpout:TEST_IDX-CLUSTER] forceTimebasedAutoLB = true autoLBFrequency = 30 server = ID01.SPLUNK-TEST.local:9997,ID02.SPLUNK-TEST.local:9997,ID03.SPLUNK-TEST.local:9997 Then i debug with this search... index="_internal" | eval bucket=_bkt | eval indextime=_indextime | table _time, indextime, bucket splunk_server _raw | convert ctime(indextime) | stats count list(*) as * by _raw | where count>1 | fields * _raw | sort - indextime Output: bucket = every bucket is another in one event count = 2 or sometimes 3 indextime = every entry is equal splunk_server = 01,02,03 or 01,01 or 02,03 or 03,03 (many different combinations) Anyone an idea? Regards - Markus
... View more