<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Universal Forwarder as buffer only in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-as-buffer-only/m-p/327647#M60842</link>
    <description>&lt;P&gt;If the intention of using a Universal Forwarder is only for a buffer to the Indexer, is it worth having one? &lt;BR /&gt;
Theory: Should there be a need to take the Indexer down for maintenance, the UF could continue to receive data and then catch the Indexer back up when maintenance is complete.&lt;BR /&gt;
Is there any other method (outside of maybe Clustered Indexer) to ensure that log data continues to flow (from say 300 inputs) to somewhere while the Indexer server is down for a short period?&lt;/P&gt;</description>
    <pubDate>Tue, 28 Feb 2017 20:40:30 GMT</pubDate>
    <dc:creator>jstockt</dc:creator>
    <dc:date>2017-02-28T20:40:30Z</dc:date>
    <item>
      <title>Universal Forwarder as buffer only</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-as-buffer-only/m-p/327647#M60842</link>
      <description>&lt;P&gt;If the intention of using a Universal Forwarder is only for a buffer to the Indexer, is it worth having one? &lt;BR /&gt;
Theory: Should there be a need to take the Indexer down for maintenance, the UF could continue to receive data and then catch the Indexer back up when maintenance is complete.&lt;BR /&gt;
Is there any other method (outside of maybe Clustered Indexer) to ensure that log data continues to flow (from say 300 inputs) to somewhere while the Indexer server is down for a short period?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2017 20:40:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-as-buffer-only/m-p/327647#M60842</guid>
      <dc:creator>jstockt</dc:creator>
      <dc:date>2017-02-28T20:40:30Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder as buffer only</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-as-buffer-only/m-p/327648#M60843</link>
      <description>&lt;P&gt;The Universal Forwarder is more than just a buffer.  Without it, how would you monitor the logs on remote (to Splunk) systems?&lt;/P&gt;

&lt;P&gt;Another method to ensure data flows while an indexer is down for service is to have multiple indexers.  If the UF is configured to forward to all indexers (and it should) then it will have an alternative path if one indexer is down.  In the normal case, your data will be distributed across several indexers for better search performance.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2017 21:56:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-as-buffer-only/m-p/327648#M60843</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2017-02-28T21:56:00Z</dc:date>
    </item>
  </channel>
</rss>

