<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can you use directory monitors in a cluster configuration? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Can-you-use-directory-monitors-in-a-cluster-configuration/m-p/186593#M37367</link>
    <description>&lt;P&gt;We have tried using the Universal Forwarder for sending logs from one of our servers to our Splunk indexer cluster using auto load balancing, but it appears to be putting too much of a load on the server causing application availability issues.  This same server was running perfectly when logs were being collected via a directory monitor by a standalone Splunk indexer.&lt;/P&gt;

&lt;P&gt;Is using a directory monitor a supported configuration for inputs in a cluster, or do I need to do something like set up a standalone UF that monitors the folders on that particular server remotely and sends them to our indexers?&lt;/P&gt;</description>
    <pubDate>Mon, 27 Oct 2014 20:19:44 GMT</pubDate>
    <dc:creator>djconroy</dc:creator>
    <dc:date>2014-10-27T20:19:44Z</dc:date>
    <item>
      <title>Can you use directory monitors in a cluster configuration?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-you-use-directory-monitors-in-a-cluster-configuration/m-p/186593#M37367</link>
      <description>&lt;P&gt;We have tried using the Universal Forwarder for sending logs from one of our servers to our Splunk indexer cluster using auto load balancing, but it appears to be putting too much of a load on the server causing application availability issues.  This same server was running perfectly when logs were being collected via a directory monitor by a standalone Splunk indexer.&lt;/P&gt;

&lt;P&gt;Is using a directory monitor a supported configuration for inputs in a cluster, or do I need to do something like set up a standalone UF that monitors the folders on that particular server remotely and sends them to our indexers?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Oct 2014 20:19:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-you-use-directory-monitors-in-a-cluster-configuration/m-p/186593#M37367</guid>
      <dc:creator>djconroy</dc:creator>
      <dc:date>2014-10-27T20:19:44Z</dc:date>
    </item>
    <item>
      <title>Re: Can you use directory monitors in a cluster configuration?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-you-use-directory-monitors-in-a-cluster-configuration/m-p/186594#M37368</link>
      <description>&lt;P&gt;I don't know what a directory monitor means in this context.&lt;/P&gt;

&lt;P&gt;Do you mean an inputs.conf &lt;CODE&gt;[monitor:///...]&lt;/CODE&gt; stanza?  If so, what were  you doing instead with your Universal Forwarder?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Oct 2014 21:50:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-you-use-directory-monitors-in-a-cluster-configuration/m-p/186594#M37368</guid>
      <dc:creator>jrodman</dc:creator>
      <dc:date>2014-10-27T21:50:26Z</dc:date>
    </item>
    <item>
      <title>Re: Can you use directory monitors in a cluster configuration?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-you-use-directory-monitors-in-a-cluster-configuration/m-p/186595#M37369</link>
      <description>&lt;P&gt;Generally speaking I would suggest, in a clustered environment, separation of data collection from cluster management.  The idea of clustering is redundancy and replace-ability.  Collecting data on a single clustering node conflicts with that idea and goal.&lt;/P&gt;

&lt;P&gt;A Universal Forwarder causing outages is pretty surprising, though its certainly possible.  Usually local log collection is more reliable than collection over network filesystems or similar, but remote log collection is a valid strategy.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Oct 2014 21:53:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-you-use-directory-monitors-in-a-cluster-configuration/m-p/186595#M37369</guid>
      <dc:creator>jrodman</dc:creator>
      <dc:date>2014-10-27T21:53:52Z</dc:date>
    </item>
    <item>
      <title>Re: Can you use directory monitors in a cluster configuration?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-you-use-directory-monitors-in-a-cluster-configuration/m-p/186596#M37370</link>
      <description>&lt;P&gt;Yes, that's what I mean by directory monitor.  I have implemented the monitor from a dedicated machine and that seemed to resolve the performance issues encountered when running the UF locally on the File Server.&lt;/P&gt;

&lt;P&gt;When the Splunk Forwarder service was running locally we saw a spike in network latency that was impacting IIS sites that use said server for Shared Configuration files.  Now with the logs being collected remotely the latency has disappeared.&lt;/P&gt;

&lt;P&gt;I am stuck with the architecture, the server in question is already a receptacle for over 80GB of logs per day from a proprietary application consisting of 10 separate IIS and application servers.  The software vendor insists that the application log to a shared server (single point of failure IMO).  I believe adding the collecting of those logs locally with the forwarder was just the straw that broke the camel's back.  I am fighting to change the architecture, but that takes time.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Nov 2014 15:22:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-you-use-directory-monitors-in-a-cluster-configuration/m-p/186596#M37370</guid>
      <dc:creator>djconroy</dc:creator>
      <dc:date>2014-11-04T15:22:23Z</dc:date>
    </item>
  </channel>
</rss>

