Hi,
After going through the 6.3.1 documentation, it is still not clear to me whether multitiered load balancing is fully supported in Splunk. I don't see why not, but I just want to double check with the community.
This is the scenario I'm thinking about:
- 100 Universal Forwarders (read logs) -> 4 Heavy Forwarders (parse and obfuscate data) -> 2 Indexers (indexing and storage)
- UFs send data to 4 HFs using load balancing . Up to 3 HFs can be down any time
- HFs send parsed data to 2 IDXs using load balancing . Up to 1 IX can be down any time
- IDXs replicate and sync with each other so that data is kept in two different places
I just want to make sure there's no single point of failure here.
Thanks,
J
↧