<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to avoid data loss on HF on restart in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-avoid-data-loss-on-HF-on-restart/m-p/388617#M69583</link>
    <description>&lt;P&gt;This is addressed partially in 8.0.1 and coming in 7.2.10, adding and removing inputs for HEC will no longer require a restart!&lt;/P&gt;</description>
    <pubDate>Tue, 28 Jan 2020 07:27:25 GMT</pubDate>
    <dc:creator>esix_splunk</dc:creator>
    <dc:date>2020-01-28T07:27:25Z</dc:date>
    <item>
      <title>How to avoid data loss on HF on restart</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-avoid-data-loss-on-HF-on-restart/m-p/388614#M69580</link>
      <description>&lt;P&gt;I have service now add on, db connect in Heavy Forwarder. So i cant use multiple instances of HF to avoid data duplication and licensing. My both apps Service Now and DB connect are in real time sync, also I need to do changes in props &amp;amp; transforms frequently. so in this case how to avoid data loss. Just using indexer ack will resolve?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2018 06:21:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-avoid-data-loss-on-HF-on-restart/m-p/388614#M69580</guid>
      <dc:creator>AnilPujar</dc:creator>
      <dc:date>2018-11-08T06:21:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to avoid data loss on HF on restart</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-avoid-data-loss-on-HF-on-restart/m-p/388615#M69581</link>
      <description>&lt;P&gt;I took the liberty of changing your post to a new question, instead of an answer to &lt;A href="https://answers.splunk.com/answers/674341/missing-of-events-and-flooding-of-data-in-heavy-fo.html"&gt;https://answers.splunk.com/answers/674341/missing-of-events-and-flooding-of-data-in-heavy-fo.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;To better understand your situation: why do you have frequent props/transforms changes that require a restart? Does this HF do other tasks, besides the SN and DBX apps (e.g. routing data from other forwarders or so)?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2018 08:41:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-avoid-data-loss-on-HF-on-restart/m-p/388615#M69581</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-11-08T08:41:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to avoid data loss on HF on restart</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-avoid-data-loss-on-HF-on-restart/m-p/388616#M69582</link>
      <description>&lt;P&gt;Hi Frank,&lt;BR /&gt;
Since I am also expecting an answer to a similar question, please find the details below.&lt;/P&gt;

&lt;P&gt;When we add a new HEC via inputs.conf in HF, we have a setting restartSplunkd = true in Serverclass associated with HEC app. So whenever we add a new HEC, we need to restart the HF's that is used to collect the HTTP inputs.&lt;/P&gt;

&lt;P&gt;Can we use restartSplunkd = false while adding a new inputs.conf ?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2020 05:30:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-avoid-data-loss-on-HF-on-restart/m-p/388616#M69582</guid>
      <dc:creator>sahilyahiya</dc:creator>
      <dc:date>2020-01-28T05:30:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to avoid data loss on HF on restart</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-avoid-data-loss-on-HF-on-restart/m-p/388617#M69583</link>
      <description>&lt;P&gt;This is addressed partially in 8.0.1 and coming in 7.2.10, adding and removing inputs for HEC will no longer require a restart!&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2020 07:27:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-avoid-data-loss-on-HF-on-restart/m-p/388617#M69583</guid>
      <dc:creator>esix_splunk</dc:creator>
      <dc:date>2020-01-28T07:27:25Z</dc:date>
    </item>
  </channel>
</rss>

