<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is it possible to prioritize what data is forwarded from a heavy forwarder? (ex: security data first, then non-security data) in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-prioritize-what-data-is-forwarded-from-a-heavy/m-p/278391#M53306</link>
    <description>&lt;P&gt;Hi, allow me to chime in. The problem is that our bandwidth is very limited (also entirely unavailable for extended time periods), thus we'd like to be able to send the priority data first as soon as we have a (stable) connection. Only after that has been sent should the less important data be forwarded.&lt;BR /&gt;
We'll be using indexer acknowledgement, so this could also be applied at the forwarding buffer level: we'd like to keep more of the important data than of the less important data queued on the forwarder, and if needed we'd also replace the queued unimportant data with the important data (we are &lt;EM&gt;really&lt;/EM&gt; limited in this environment, otherwise we'd simply keep everything on the HF).&lt;/P&gt;</description>
    <pubDate>Thu, 29 Oct 2015 07:36:57 GMT</pubDate>
    <dc:creator>jeffland</dc:creator>
    <dc:date>2015-10-29T07:36:57Z</dc:date>
    <item>
      <title>Is it possible to prioritize what data is forwarded from a heavy forwarder? (ex: security data first, then non-security data)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-prioritize-what-data-is-forwarded-from-a-heavy/m-p/278388#M53303</link>
      <description>&lt;P&gt;Hi everybody,&lt;/P&gt;

&lt;P&gt;I'm new in Splunk, so be gentle, please.&lt;/P&gt;

&lt;P&gt;So that's the scenario:&lt;/P&gt;

&lt;P&gt;I have a Splunk Heavy forwarder, and I want to know if it is possible to prioritize the data which is forwarded to the indexer(s)?&lt;/P&gt;

&lt;P&gt;For example: I have security relevant log data and I want this data to be forwarded first, every time. So that non-security relevant data is held back until the security relevant data is indexed.&lt;/P&gt;

&lt;P&gt;Is that possible and how?&lt;/P&gt;

&lt;P&gt;If possible, looking for solutions which are built-in to out-of-box Splunk, add-ons etc. I can't use another software for it since the system Splunk is running on is already pretty limited.&lt;/P&gt;

&lt;P&gt;Thank you &lt;/P&gt;

&lt;P&gt;David&lt;/P&gt;</description>
      <pubDate>Wed, 21 Oct 2015 08:45:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-prioritize-what-data-is-forwarded-from-a-heavy/m-p/278388#M53303</guid>
      <dc:creator>dkeck</dc:creator>
      <dc:date>2015-10-21T08:45:19Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to prioritize what data is forwarded from a heavy forwarder? (ex: security data first, then non-security data)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-prioritize-what-data-is-forwarded-from-a-heavy/m-p/278389#M53304</link>
      <description>&lt;P&gt;Nobody has an answer? too bad.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2015 11:20:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-prioritize-what-data-is-forwarded-from-a-heavy/m-p/278389#M53304</guid>
      <dc:creator>dkeck</dc:creator>
      <dc:date>2015-10-26T11:20:26Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to prioritize what data is forwarded from a heavy forwarder? (ex: security data first, then non-security data)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-prioritize-what-data-is-forwarded-from-a-heavy/m-p/278390#M53305</link>
      <description>&lt;P&gt;What problems are you experiencing that you feel needs to be solved with prioritization of certain logs/data over other logs/data?  Are you having problems out of your indexer, since it's already at the edge of overloaded?  &lt;/P&gt;

&lt;P&gt;But a thought, not perfect but at least something - if you ran two copies of Splunk as forwarders, you could prioritize the processes themselves, cranking one way down to "idle" time processing and the other leaving at normal.  That &lt;EM&gt;could&lt;/EM&gt; make a minor change in how each would behave. &lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2015 01:28:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-prioritize-what-data-is-forwarded-from-a-heavy/m-p/278390#M53305</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2015-10-28T01:28:01Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to prioritize what data is forwarded from a heavy forwarder? (ex: security data first, then non-security data)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-prioritize-what-data-is-forwarded-from-a-heavy/m-p/278391#M53306</link>
      <description>&lt;P&gt;Hi, allow me to chime in. The problem is that our bandwidth is very limited (also entirely unavailable for extended time periods), thus we'd like to be able to send the priority data first as soon as we have a (stable) connection. Only after that has been sent should the less important data be forwarded.&lt;BR /&gt;
We'll be using indexer acknowledgement, so this could also be applied at the forwarding buffer level: we'd like to keep more of the important data than of the less important data queued on the forwarder, and if needed we'd also replace the queued unimportant data with the important data (we are &lt;EM&gt;really&lt;/EM&gt; limited in this environment, otherwise we'd simply keep everything on the HF).&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2015 07:36:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-prioritize-what-data-is-forwarded-from-a-heavy/m-p/278391#M53306</guid>
      <dc:creator>jeffland</dc:creator>
      <dc:date>2015-10-29T07:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to prioritize what data is forwarded from a heavy forwarder? (ex: security data first, then non-security data)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-prioritize-what-data-is-forwarded-from-a-heavy/m-p/278392#M53307</link>
      <description>&lt;P&gt;Thanks, that explanation of &lt;EM&gt;why&lt;/EM&gt; you need it will probably help folks trying to answer this!&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2015 12:03:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-prioritize-what-data-is-forwarded-from-a-heavy/m-p/278392#M53307</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2015-10-29T12:03:03Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to prioritize what data is forwarded from a heavy forwarder? (ex: security data first, then non-security data)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-prioritize-what-data-is-forwarded-from-a-heavy/m-p/278393#M53308</link>
      <description>&lt;P&gt;The only answer I have is one that you won't really benefit from. We had Splunk Pro Services visit us and one of the questions that came up was this exact question. Splunk does not have any prioritization ability according to them, hopefully someone will correct me if this was wrong but that is what we were told.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2016 16:19:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-prioritize-what-data-is-forwarded-from-a-heavy/m-p/278393#M53308</guid>
      <dc:creator>ryandg</dc:creator>
      <dc:date>2016-04-18T16:19:58Z</dc:date>
    </item>
  </channel>
</rss>

