<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to set up a high available syslog drain for cloud foundry to Splunk? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-up-a-high-available-syslog-drain-for-cloud-foundry-to/m-p/117616#M24459</link>
    <description>&lt;P&gt;Finally!!!. Thanks @rarsan_splunk . &lt;/P&gt;</description>
    <pubDate>Sat, 07 Jul 2018 11:10:32 GMT</pubDate>
    <dc:creator>sgp0637</dc:creator>
    <dc:date>2018-07-07T11:10:32Z</dc:date>
    <item>
      <title>How to set up a high available syslog drain for cloud foundry to Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-up-a-high-available-syslog-drain-for-cloud-foundry-to/m-p/117614#M24457</link>
      <description>&lt;P&gt;We have a cloud foundry set up and wants to forward the logs to splunk as syslog drain. The TCP/UDP input method is not ideal since the restart of the index will cause loss of data.&lt;/P&gt;

&lt;P&gt;Moreover, the need for change in inputs.conf will be more often (planning to create the data forwarding on demand basis from different clients) which in turn will cause multiple restart of the indexer as well.&lt;/P&gt;

&lt;P&gt;We are running an indexer cluster and a rolling restart is possible but again a load-balancer and a re-configuration of same is needed to communicate to load balancer not to send any data to the indexer which is being restarted. [ load balancer is needed here since there are no forwarders involved]&lt;/P&gt;

&lt;P&gt;To have a separate syslong-ng or a forwarder is also not an option since its adding more components and complicating high availability set up&lt;/P&gt;

&lt;P&gt;If you have done any HA set up for cloud foundry - splunk integration, please share . &lt;/P&gt;

&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2015 08:37:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-up-a-high-available-syslog-drain-for-cloud-foundry-to/m-p/117614#M24457</guid>
      <dc:creator>sgp0637</dc:creator>
      <dc:date>2015-07-13T08:37:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to set up a high available syslog drain for cloud foundry to Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-up-a-high-available-syslog-drain-for-cloud-foundry-to/m-p/117615#M24458</link>
      <description>&lt;P&gt;Take a look at the recently released &lt;A href="https://github.com/cloudfoundry-community/splunk-firehose-nozzle-release"&gt;Splunk Firehose Nozzle for Cloud Foundry&lt;/A&gt;.&lt;BR /&gt;
It's an HA setup to stream logs &amp;amp; metrics from Cloud Foundry Firehose to your Splunk deployment in a scalable, reliable and secure fashion. There's also a supporting &lt;A href="https://splunkbase.splunk.com/app/3417/#/details"&gt;Add-on&lt;/A&gt; to help visualize the data. More details here:&lt;BR /&gt;
&lt;A href="https://github.com/splunk/splunk-addon-for-cloud-foundry"&gt;https://github.com/splunk/splunk-addon-for-cloud-foundry&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jan 2017 22:22:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-up-a-high-available-syslog-drain-for-cloud-foundry-to/m-p/117615#M24458</guid>
      <dc:creator>rarsan_splunk</dc:creator>
      <dc:date>2017-01-12T22:22:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to set up a high available syslog drain for cloud foundry to Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-up-a-high-available-syslog-drain-for-cloud-foundry-to/m-p/117616#M24459</link>
      <description>&lt;P&gt;Finally!!!. Thanks @rarsan_splunk . &lt;/P&gt;</description>
      <pubDate>Sat, 07 Jul 2018 11:10:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-up-a-high-available-syslog-drain-for-cloud-foundry-to/m-p/117616#M24459</guid>
      <dc:creator>sgp0637</dc:creator>
      <dc:date>2018-07-07T11:10:32Z</dc:date>
    </item>
  </channel>
</rss>

