<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk light weight forwarder failover capability in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-light-weight-forwarder-failover-capability/m-p/30226#M5259</link>
    <description>&lt;P&gt;Multiple forwarders on the same machine reading and forwarding the same files is a disaster waiting to happen.  Each forwarder keeps a database of what files it has seen and how far into them it has forwarded.  A "fail over" forwarder running on the same machine would very likely result in lots of duplicate events.&lt;/P&gt;

&lt;P&gt;I would try to think of the Splunk forwarder as an agent.  You don't run "fail over" antivirus software, or "fail over" ssh daemons.  As bosburn suggests, watching inactive forwarders via deployment monitor or a watchdog to restart a forwarder if it does crash makes sense.  But don't overcomplicate it.&lt;/P&gt;</description>
    <pubDate>Fri, 10 May 2013 18:16:54 GMT</pubDate>
    <dc:creator>dwaddle</dc:creator>
    <dc:date>2013-05-10T18:16:54Z</dc:date>
    <item>
      <title>Splunk light weight forwarder failover capability</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-light-weight-forwarder-failover-capability/m-p/30223#M5256</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Do we  have a fail over capability for any Splunk forwarders? like if one forwarder goes down the other one will pickup and start reading the files where  the other forwarder stopped&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2013 17:46:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-light-weight-forwarder-failover-capability/m-p/30223#M5256</guid>
      <dc:creator>ajaybguthi</dc:creator>
      <dc:date>2013-05-10T17:46:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk light weight forwarder failover capability</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-light-weight-forwarder-failover-capability/m-p/30224#M5257</link>
      <description>&lt;P&gt;This functionality is not included in the base Splunk forwarder install.  You &lt;EM&gt;could&lt;/EM&gt; use deployment monitor app to watch for forwarders that stop sending data, or write a watchdog script that will keep an eye out on the Splunk process and restart it if it crashes.&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2013 18:06:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-light-weight-forwarder-failover-capability/m-p/30224#M5257</guid>
      <dc:creator>bosburn_splunk</dc:creator>
      <dc:date>2013-05-10T18:06:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk light weight forwarder failover capability</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-light-weight-forwarder-failover-capability/m-p/30225#M5258</link>
      <description>&lt;P&gt;first upgoat!&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2013 18:08:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-light-weight-forwarder-failover-capability/m-p/30225#M5258</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2013-05-10T18:08:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk light weight forwarder failover capability</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-light-weight-forwarder-failover-capability/m-p/30226#M5259</link>
      <description>&lt;P&gt;Multiple forwarders on the same machine reading and forwarding the same files is a disaster waiting to happen.  Each forwarder keeps a database of what files it has seen and how far into them it has forwarded.  A "fail over" forwarder running on the same machine would very likely result in lots of duplicate events.&lt;/P&gt;

&lt;P&gt;I would try to think of the Splunk forwarder as an agent.  You don't run "fail over" antivirus software, or "fail over" ssh daemons.  As bosburn suggests, watching inactive forwarders via deployment monitor or a watchdog to restart a forwarder if it does crash makes sense.  But don't overcomplicate it.&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2013 18:16:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-light-weight-forwarder-failover-capability/m-p/30226#M5259</guid>
      <dc:creator>dwaddle</dc:creator>
      <dc:date>2013-05-10T18:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk light weight forwarder failover capability</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-light-weight-forwarder-failover-capability/m-p/30227#M5260</link>
      <description>&lt;P&gt;inb4--oh dammit.&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2013 18:57:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-light-weight-forwarder-failover-capability/m-p/30227#M5260</guid>
      <dc:creator>piebob</dc:creator>
      <dc:date>2013-05-10T18:57:19Z</dc:date>
    </item>
  </channel>
</rss>

