<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Store and Forward HA in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Store-and-Forward-HA/m-p/53385#M10296</link>
    <description>&lt;P&gt;Thank you for the suggestion. Cool idea, but we cannot purchase and install more hardware at the client site, it's government...&lt;/P&gt;</description>
    <pubDate>Fri, 08 Mar 2013 19:07:56 GMT</pubDate>
    <dc:creator>ephemeric</dc:creator>
    <dc:date>2013-03-08T19:07:56Z</dc:date>
    <item>
      <title>Splunk Store and Forward HA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Store-and-Forward-HA/m-p/53382#M10293</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;

&lt;P&gt;Forgive my hasty question, it's late and my articulation has dwindled along with my brain capacity...&lt;/P&gt;

&lt;P&gt;We need a solution that allows us to not lose any events whatsoever on a collector, AKA heavy forwarder.&lt;/P&gt;

&lt;P&gt;We can't do persistent queues across all inouts as splunktcp-ssl inputs do not allow this. We want all inputs to go straight into Splunk, no syslog relays etc.&lt;/P&gt;

&lt;P&gt;The index and forward function won't work for us as it counts toward licence usage. How would one check to see what events were not acknowledged anyway? I assume something would have to be hacked into place to check which events were received?&lt;/P&gt;

&lt;P&gt;I thought of writing something that monitors and then stops splunkd, copies over another outputs.conf (with no forward servers configured) and starts Splunk which indexes locally and similarly repeats when uplink is back.&lt;/P&gt;

&lt;P&gt;I have noticed if all forward servers are removed from outputs.conf, either at start or via CLI one at a time then Splunk automatically starts to index locally on the fly.&lt;/P&gt;

&lt;P&gt;This is ideal as it happens on the fly and no event loss I presume? This seems to be the closest solution I could find except that adding forward servers one at a time caused our data to be cloned in triplicate. Ouch!&lt;/P&gt;

&lt;P&gt;We don't want to do cloning, hell no, we assume one uplink in each scenario.&lt;/P&gt;

&lt;P&gt;We have three receivers (indexers) on the remote side but only one uplink.&lt;/P&gt;

&lt;P&gt;I'm lost, how can we get Splunk to index locally ONLY when the uplink is unavailable and hence the event is not ack'ed and then merge those buckets/events out of band at a later stage?&lt;/P&gt;

&lt;P&gt;It would be perfect if we could put all not ack'ed events into an index somehow on the localhost after a timeout and then when back online to forward those same events, get them ack'ed and clean out the local index.&lt;/P&gt;

&lt;P&gt;This I know how, force a roll of the last hot and then scrub the ids and scp the warm buckets upstream into an indexer and merge and restart.&lt;/P&gt;

&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2013 19:09:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Store-and-Forward-HA/m-p/53382#M10293</guid>
      <dc:creator>ephemeric</dc:creator>
      <dc:date>2013-03-06T19:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Store and Forward HA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Store-and-Forward-HA/m-p/53383#M10294</link>
      <description>&lt;P&gt;Another idea I had was to forward to the instance itself when the uplink was down, to a separate out-of-band index so to speak and then merge this later. &lt;/P&gt;

&lt;P&gt;I couldn't get Splunk to forward to itself?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2013 19:13:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Store-and-Forward-HA/m-p/53383#M10294</guid>
      <dc:creator>ephemeric</dc:creator>
      <dc:date>2013-03-06T19:13:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Store and Forward HA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Store-and-Forward-HA/m-p/53384#M10295</link>
      <description>&lt;P&gt;Why not use multiple intermediate HFs with load balancing coupled with Indexer acknowledgement.  The source Forwarder, intermediate, and Indexer would all have to acknowledge events before they are removed from the queues. You would then increase your queue sizes for input and output to an accept size before the HF stop processing new events.  You could also increase your source forwarders output queue.  Items will stay these queues until the indexer are function and acknowledging events.  I can elaborate if needed.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2013 18:52:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Store-and-Forward-HA/m-p/53384#M10295</guid>
      <dc:creator>bmacias84</dc:creator>
      <dc:date>2013-03-08T18:52:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Store and Forward HA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Store-and-Forward-HA/m-p/53385#M10296</link>
      <description>&lt;P&gt;Thank you for the suggestion. Cool idea, but we cannot purchase and install more hardware at the client site, it's government...&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2013 19:07:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Store-and-Forward-HA/m-p/53385#M10296</guid>
      <dc:creator>ephemeric</dc:creator>
      <dc:date>2013-03-08T19:07:56Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Store and Forward HA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Store-and-Forward-HA/m-p/53386#M10297</link>
      <description>&lt;P&gt;use Indexer acknowledgement between the FW and Indexer.  Then increase client output queue (will use more ram).  Once the queue is full the FW will stop forwarding events.  The FW will then pickup where it left of from once the queue has been processed.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2013 19:46:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Store-and-Forward-HA/m-p/53386#M10297</guid>
      <dc:creator>bmacias84</dc:creator>
      <dc:date>2013-03-08T19:46:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Store and Forward HA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Store-and-Forward-HA/m-p/53387#M10298</link>
      <description>&lt;P&gt;We need something that can tolerate hours, maybe days of downtime.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2013 20:42:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Store-and-Forward-HA/m-p/53387#M10298</guid>
      <dc:creator>ephemeric</dc:creator>
      <dc:date>2013-03-08T20:42:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Store and Forward HA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Store-and-Forward-HA/m-p/53388#M10299</link>
      <description>&lt;P&gt;Ya I dont see the problem that solution. It will work for everything expect streaming data such as perfmon, SNMP, UDP data, etc.  Data resilance requires additional hardware (physical or virtual).&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2013 20:49:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Store-and-Forward-HA/m-p/53388#M10299</guid>
      <dc:creator>bmacias84</dc:creator>
      <dc:date>2013-03-08T20:49:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Store and Forward HA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Store-and-Forward-HA/m-p/53389#M10300</link>
      <description>&lt;P&gt;We have those other inputs too. Don't want to mess with persistent queues.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2013 20:54:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Store-and-Forward-HA/m-p/53389#M10300</guid>
      <dc:creator>ephemeric</dc:creator>
      <dc:date>2013-03-08T20:54:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Store and Forward HA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Store-and-Forward-HA/m-p/53390#M10301</link>
      <description>&lt;P&gt;If the heavy forwarder has access to a semi-persistent data source (log files) then it does this out of the box.&lt;/P&gt;

&lt;P&gt;If the data source is something else (like udp input) then I encourage you to render these as logfiles eg via rsyslogd.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2013 10:59:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Store-and-Forward-HA/m-p/53390#M10301</guid>
      <dc:creator>jrodman</dc:creator>
      <dc:date>2013-03-12T10:59:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Store and Forward HA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Store-and-Forward-HA/m-p/53391#M10302</link>
      <description>&lt;P&gt;We could do that but what about the inputs that do not support persistent queues? Like splunktcp-ssl? Because of our high security client sites, we don't have any access to forwarders on hosts to change anything, like Windows event log buffers etc. We get to install it once and then hope for the best.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2013 11:08:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Store-and-Forward-HA/m-p/53391#M10302</guid>
      <dc:creator>ephemeric</dc:creator>
      <dc:date>2013-03-12T11:08:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Store and Forward HA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Store-and-Forward-HA/m-p/53392#M10303</link>
      <description>&lt;UL&gt;
&lt;LI&gt;splunktcp-ssl isn't really an original input, but a forwarding mechanism.  Splunk forwarding, as discussed in your forwarding question, has the ack mechanism to ensure the datastream is handed off cleanly.&lt;/LI&gt;
&lt;LI&gt;persistent-queues are not really a way to provide data redundancy, but instead a way to provide queue buffering  elasticity.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 12 Mar 2013 17:13:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Store-and-Forward-HA/m-p/53392#M10303</guid>
      <dc:creator>jrodman</dc:creator>
      <dc:date>2013-03-12T17:13:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Store and Forward HA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Store-and-Forward-HA/m-p/53393#M10304</link>
      <description>&lt;UL&gt;
&lt;LI&gt;WinEvent live channels should be made to behave similarly to to Monitor / Tailing, but without walking the code I have doubts that it correctly advances its event checkpoints in the same manner as tailing.  For .evt files, Tailling tracks whether they have been read, so they should behave properly.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 12 Mar 2013 17:13:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Store-and-Forward-HA/m-p/53393#M10304</guid>
      <dc:creator>jrodman</dc:creator>
      <dc:date>2013-03-12T17:13:21Z</dc:date>
    </item>
  </channel>
</rss>

