<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Heavy forwarder redundancy and HA in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-redundancy-and-HA/m-p/371574#M67449</link>
    <description>&lt;P&gt;Hi noybin,&lt;BR /&gt;
to have HA on Heavy forwarders you have to use at least two HFs, then you have to configure your Universal Forwarders (if present) in auto load balancing addressing both the HFs.&lt;/P&gt;

&lt;P&gt;If you have syslog traffic, you have to use in addition a load balancer between appliances and HFs to be sure that syslog traffic is distributed to both the HFs in normal working and to the running one in fault situation.&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
    <pubDate>Thu, 16 Nov 2017 10:39:03 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2017-11-16T10:39:03Z</dc:date>
    <item>
      <title>Heavy forwarder redundancy and HA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-redundancy-and-HA/m-p/371572#M67447</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;My client needs High Availability in the heavy forwarders.&lt;/P&gt;

&lt;P&gt;They are collecting events from devices on a datacenter and sending to the indexer in another datacenter.&lt;BR /&gt;
Those events are sent through a Heavy Forwarder. So they need that HF to have HA. &lt;/P&gt;

&lt;P&gt;Is there a way to ceate a cluster of the Heavy forwarders so in case one is down, the other starts getting the events and sending them to the indexer?&lt;/P&gt;

&lt;P&gt;If not, how can we achieve HA in this architecture?&lt;/P&gt;

&lt;P&gt;Thank you very much&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2017 18:08:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-redundancy-and-HA/m-p/371572#M67447</guid>
      <dc:creator>noybin</dc:creator>
      <dc:date>2017-11-15T18:08:35Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy forwarder redundancy and HA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-redundancy-and-HA/m-p/371573#M67448</link>
      <description>&lt;P&gt;Use autoLB across all the HFs from the UFs.&lt;BR /&gt;&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/SplunkCloud/6.6.3/Forwarding/Configureforwarderswithoutputs.confd"&gt;http://docs.splunk.com/Documentation/SplunkCloud/6.6.3/Forwarding/Configureforwarderswithoutputs.confd&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2017 22:18:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-redundancy-and-HA/m-p/371573#M67448</guid>
      <dc:creator>starcher</dc:creator>
      <dc:date>2017-11-15T22:18:30Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy forwarder redundancy and HA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-redundancy-and-HA/m-p/371574#M67449</link>
      <description>&lt;P&gt;Hi noybin,&lt;BR /&gt;
to have HA on Heavy forwarders you have to use at least two HFs, then you have to configure your Universal Forwarders (if present) in auto load balancing addressing both the HFs.&lt;/P&gt;

&lt;P&gt;If you have syslog traffic, you have to use in addition a load balancer between appliances and HFs to be sure that syslog traffic is distributed to both the HFs in normal working and to the running one in fault situation.&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2017 10:39:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-redundancy-and-HA/m-p/371574#M67449</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-11-16T10:39:03Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy forwarder redundancy and HA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-redundancy-and-HA/m-p/540045#M90430</link>
      <description>&lt;P&gt;Does the configuration changes in one heavy forwarder will also replicate the same in other heavy forwarder too while it is in cluster mode?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 05:20:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-redundancy-and-HA/m-p/540045#M90430</guid>
      <dc:creator>rajasha</dc:creator>
      <dc:date>2021-02-16T05:20:24Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy forwarder redundancy and HA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-redundancy-and-HA/m-p/540058#M90436</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/109754"&gt;@rajasha&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;yes, you have to maintain the same configurations on both the&amp;nbsp;Heavy Forwarders.&lt;/P&gt;&lt;P&gt;you could manage the HFs using the Deployment Server to be sure that both the HFs have the same configurations, this is a good solution if you have to ingest only logs from Universal Forwarders.&lt;/P&gt;&lt;P&gt;Instead there's a problem if you're using HFs to ingest syslogs because in this way you don't control the Splunk restart and it could happen at the same time and this isn't acceptable is you're ingesting syslogs.&lt;/P&gt;&lt;P&gt;In this case I hint to manually manage configurations.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 08:10:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-redundancy-and-HA/m-p/540058#M90436</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-02-16T08:10:48Z</dc:date>
    </item>
  </channel>
</rss>

