<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Universal Forwarder Data Recovery Following a Network Issue in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Universal-Forwarder-Data-Recovery-Following-a-Network/m-p/179625#M6683</link>
    <description>&lt;P&gt;Splunk operates over TCP, so you don't lose data, although if your network outage lasts a long time you can find it starts chewing through memory.  Once the connection restores it will eventually catch up automatically (provided it has the bandwidth).&lt;/P&gt;</description>
    <pubDate>Tue, 12 Aug 2014 22:58:54 GMT</pubDate>
    <dc:creator>grijhwani</dc:creator>
    <dc:date>2014-08-12T22:58:54Z</dc:date>
    <item>
      <title>Splunk Universal Forwarder Data Recovery Following a Network Issue</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Universal-Forwarder-Data-Recovery-Following-a-Network/m-p/179624#M6682</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Just wondering if anyone has encountered the following issue.  &lt;/P&gt;

&lt;P&gt;I want to setup a distributed Splunk environment consisting of one indexer and multiple forwarders, let's say 6. The forwarders will be installed on a different network and must pass through a firewall in order to contact the indexer. If, for some reason, the network drops and the forwarders are unable to contact the indexer, what happends in this case?&lt;/P&gt;

&lt;P&gt;-Do the forwarders stop sending data immediately?  &lt;/P&gt;

&lt;P&gt;-Will I lose some data from the files that the forwarders are monitoring?  &lt;/P&gt;

&lt;P&gt;-Is there a clean and elegant way to synchronize the files being monitored by the forwarders and the events on the indexer?  &lt;/P&gt;

&lt;P&gt;I am trying to setup Splunk on a production environment and having all of the events produced on the servers is crucial. &lt;/P&gt;

&lt;P&gt;Has anyone had a similar issue and found a reliable solution?&lt;/P&gt;

&lt;P&gt;Any help would be greatly appreciated!&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Aug 2014 21:17:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Universal-Forwarder-Data-Recovery-Following-a-Network/m-p/179624#M6682</guid>
      <dc:creator>splunkmasterfle</dc:creator>
      <dc:date>2014-08-12T21:17:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal Forwarder Data Recovery Following a Network Issue</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Universal-Forwarder-Data-Recovery-Following-a-Network/m-p/179625#M6683</link>
      <description>&lt;P&gt;Splunk operates over TCP, so you don't lose data, although if your network outage lasts a long time you can find it starts chewing through memory.  Once the connection restores it will eventually catch up automatically (provided it has the bandwidth).&lt;/P&gt;</description>
      <pubDate>Tue, 12 Aug 2014 22:58:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Universal-Forwarder-Data-Recovery-Following-a-Network/m-p/179625#M6683</guid>
      <dc:creator>grijhwani</dc:creator>
      <dc:date>2014-08-12T22:58:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal Forwarder Data Recovery Following a Network Issue</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Universal-Forwarder-Data-Recovery-Following-a-Network/m-p/179626#M6684</link>
      <description>&lt;P&gt;Is this information taken from the splunk documentation ?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Aug 2014 20:49:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Universal-Forwarder-Data-Recovery-Following-a-Network/m-p/179626#M6684</guid>
      <dc:creator>splunkmasterfle</dc:creator>
      <dc:date>2014-08-14T20:49:40Z</dc:date>
    </item>
  </channel>
</rss>

