<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: syslog redundancy in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/syslog-redundancy/m-p/431065#M75445</link>
    <description>&lt;P&gt;This is usually done on the load-balancer which should be configured with the 2nd server as hot-standby.  We have exactly this setup.  We have a UF that handles syslog via syslog-ng.  We have a HF that handles HEC, DBConnect, etc., and this also runs syslog-ng but we never expect anything to come except in an emergency.  We do it this way because HF is exceedingly inefficient and an intermediary, compared to UF, so we always prefer the UF route.&lt;/P&gt;</description>
    <pubDate>Tue, 10 Jul 2018 16:11:49 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2018-07-10T16:11:49Z</dc:date>
    <item>
      <title>syslog redundancy</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-redundancy/m-p/431063#M75443</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I'd like to setup active-failover redundancy instead of time based load balancing on heavy forwarder routing syslog to third party system (syslog-ng) Is it possible somehow ?&lt;/P&gt;

&lt;P&gt;The main problem if i config syslog routing to both syslog-ng server, and one of them fail, the whole routing process will be stopped on the heavy forwarder as well.&lt;/P&gt;

&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jul 2018 14:36:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-redundancy/m-p/431063#M75443</guid>
      <dc:creator>szrobag</dc:creator>
      <dc:date>2018-07-10T14:36:44Z</dc:date>
    </item>
    <item>
      <title>Re: syslog redundancy</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-redundancy/m-p/431064#M75444</link>
      <description>&lt;P&gt;Couple of options:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;some kind of network load balancer in front of the syslog-ng servers that provides the HF with a single, highly available destination, abstracting from which syslog server actually receives the data&lt;/LI&gt;
&lt;LI&gt;keepalived (or something similar) on the syslog-ng servers, where the passive server takes over the IP address of the active server when the active server goes down&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 10 Jul 2018 15:56:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-redundancy/m-p/431064#M75444</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-07-10T15:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: syslog redundancy</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-redundancy/m-p/431065#M75445</link>
      <description>&lt;P&gt;This is usually done on the load-balancer which should be configured with the 2nd server as hot-standby.  We have exactly this setup.  We have a UF that handles syslog via syslog-ng.  We have a HF that handles HEC, DBConnect, etc., and this also runs syslog-ng but we never expect anything to come except in an emergency.  We do it this way because HF is exceedingly inefficient and an intermediary, compared to UF, so we always prefer the UF route.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jul 2018 16:11:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-redundancy/m-p/431065#M75445</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2018-07-10T16:11:49Z</dc:date>
    </item>
    <item>
      <title>Re: syslog redundancy</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-redundancy/m-p/431066#M75446</link>
      <description>&lt;P&gt;Thank you guys. As i see splunk has no native support for this scenario....&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2018 08:19:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-redundancy/m-p/431066#M75446</guid>
      <dc:creator>ipteam</dc:creator>
      <dc:date>2018-07-11T08:19:29Z</dc:date>
    </item>
    <item>
      <title>Re: syslog redundancy</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-redundancy/m-p/431067#M75447</link>
      <description>&lt;P&gt;Not true, you can send syslog directly to Indexers but it is not advised and tends to create unacceptible data loss.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2018 15:24:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-redundancy/m-p/431067#M75447</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2018-07-11T15:24:19Z</dc:date>
    </item>
  </channel>
</rss>

