We are running in an index cluster with 53 indxers and are findind that our high volume sources cause data imbalance. We have this index cluster behind an AWS ELB. The high data sources seem "sticky" with what index they write to, therefore causing imbalances. I am looking to use index discovery in my next build in hopes this will mitigate some of this behavior and be more intelligent where the data writes.
This data source comes into an HEC tier and then off to the indexer. The index rebalance seems to be working fine but I want to try to avoid this issue as a whole!
Any thoughts are welcome. Thanks in advance!
↧