Understanding typical outages

With a single Splunk instance, an outage-perhaps for an operating system upgrade-will cause events to queue on the Splunk forwarder instances. If there are multiple indexers, the forwarders will continue to send events to the remaining indexers.

Let's walk through a simplified scenario. Given these four machines, with the forwarders configured to load balance their output across two indexers, as shown in the following diagram:

While everything is running, half of the events from each forwarder data will be sent to each indexer. If one indexer is down, we are left with only one indexer as shown in the diagram: ...

Get Implementing Splunk 7 - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.