<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How much data should be sent to one forwarder? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-much-data-should-be-sent-to-one-forwarder/m-p/414218#M73265</link>
    <description>&lt;P&gt;are we talking a physical appliance? I was hopping something like HAProxy or LVS would suffice. &lt;/P&gt;</description>
    <pubDate>Wed, 31 Jul 2019 10:54:14 GMT</pubDate>
    <dc:creator>nkingsbury</dc:creator>
    <dc:date>2019-07-31T10:54:14Z</dc:date>
    <item>
      <title>How much data should be sent to one forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-much-data-should-be-sent-to-one-forwarder/m-p/414213#M73260</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
I am setting up a log collector with a Universal Forwarder attached for collecting network logs (syslog-ng) and then sending them to Splunk Cloud.&lt;/P&gt;

&lt;P&gt;I am wondering if there is a good rule of thumb/best practice as to how many devices, or how much data should be sent to one collector/forwarder.&lt;/P&gt;

&lt;P&gt;I plan to collect logs from: 6 firewalls, 32 routers, 165 switches, as well as some software logs like Cisco ISE. &lt;/P&gt;

&lt;P&gt;All of those devices are spread around the world. Should I set up collectors in regional data-centers, or would I be OK sending everything to one?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2019 17:56:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-much-data-should-be-sent-to-one-forwarder/m-p/414213#M73260</guid>
      <dc:creator>nkingsbury</dc:creator>
      <dc:date>2019-07-25T17:56:54Z</dc:date>
    </item>
    <item>
      <title>Re: How much data should be sent to one forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-much-data-should-be-sent-to-one-forwarder/m-p/414214#M73261</link>
      <description>&lt;P&gt;A better measure than number of devices is data rate.  A UF should have no problem with 256 KB/s or more.  IF you're still concerned, stand up multiple syslog-ng servers (with UFs) behind a load balancer.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jul 2019 16:45:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-much-data-should-be-sent-to-one-forwarder/m-p/414214#M73261</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-07-26T16:45:50Z</dc:date>
    </item>
    <item>
      <title>Re: How much data should be sent to one forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-much-data-should-be-sent-to-one-forwarder/m-p/414215#M73262</link>
      <description>&lt;P&gt;I would do 2 behind a load balancer to give you some fault-tolerance through redundancy.  That load can be handled by just one when one of them dies.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jul 2019 20:27:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-much-data-should-be-sent-to-one-forwarder/m-p/414215#M73262</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-07-26T20:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: How much data should be sent to one forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-much-data-should-be-sent-to-one-forwarder/m-p/414216#M73263</link>
      <description>&lt;P&gt;Thank you for the answer. It seems to be the common consensus that I should have a load balancer  in front of my collectors. Let me spell this out a bit becuase I am quite new to this and I cant find documentation for exactly what I am doing.&lt;/P&gt;

&lt;P&gt;So, I will point my network device syslogs at a load balancer, that load balancer is setup to send the traffic to two different syslog-ng/UF's, which then forward the logs up to the cloud indexers. &lt;/P&gt;

&lt;P&gt;Is there a recommended load balancer product to use for this case? &lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2019 02:36:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-much-data-should-be-sent-to-one-forwarder/m-p/414216#M73263</guid>
      <dc:creator>nkingsbury</dc:creator>
      <dc:date>2019-07-31T02:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: How much data should be sent to one forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-much-data-should-be-sent-to-one-forwarder/m-p/414217#M73264</link>
      <description>&lt;P&gt;Well, don't forget that your load balancer must be HA as well - and yes F5 does a pretty decent job in handling the Splunk traffic.&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2019 10:48:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-much-data-should-be-sent-to-one-forwarder/m-p/414217#M73264</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2019-07-31T10:48:44Z</dc:date>
    </item>
    <item>
      <title>Re: How much data should be sent to one forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-much-data-should-be-sent-to-one-forwarder/m-p/414218#M73265</link>
      <description>&lt;P&gt;are we talking a physical appliance? I was hopping something like HAProxy or LVS would suffice. &lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2019 10:54:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-much-data-should-be-sent-to-one-forwarder/m-p/414218#M73265</guid>
      <dc:creator>nkingsbury</dc:creator>
      <dc:date>2019-07-31T10:54:14Z</dc:date>
    </item>
    <item>
      <title>Re: How much data should be sent to one forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-much-data-should-be-sent-to-one-forwarder/m-p/414219#M73266</link>
      <description>&lt;P&gt;Yes, that will work, too.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2019 18:19:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-much-data-should-be-sent-to-one-forwarder/m-p/414219#M73266</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-07-31T18:19:26Z</dc:date>
    </item>
  </channel>
</rss>

