<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: syslog forwarding data with HA in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/syslog-forwarding-data-with-HA/m-p/507509#M86371</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/193316"&gt;@surekhasplunk&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;in normal working, are you seeing all the logs or not?&lt;/P&gt;&lt;P&gt;did you tried to turn off one of the syslogs servers?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Mon, 06 Jul 2020 09:40:45 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2020-07-06T09:40:45Z</dc:date>
    <item>
      <title>syslog forwarding data with HA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-forwarding-data-with-HA/m-p/507383#M86340</link>
      <description>&lt;P&gt;I have two syslog servers syslog1 and syslog2&lt;/P&gt;&lt;P&gt;For all of the sources i am getting the data into both the syslog servers but indexing data from 1 syslog.&lt;/P&gt;&lt;P&gt;But for one of the sources i a receiving data only on one syslog server that is syslog1 and not on syslog2.&lt;/P&gt;&lt;P&gt;But everything else right now is getting forwarder from syslog2.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now i dont know how and where to start trouble shooting from&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jul 2020 01:45:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-forwarding-data-with-HA/m-p/507383#M86340</guid>
      <dc:creator>surekhasplunk</dc:creator>
      <dc:date>2020-07-05T01:45:15Z</dc:date>
    </item>
    <item>
      <title>Re: syslog forwarding data with HA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-forwarding-data-with-HA/m-p/507393#M86344</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/193316"&gt;@surekhasplunk&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;you spoke of HA, does this mean that you have also a Load Balancer in front of the two syslog servers?&lt;/P&gt;&lt;P&gt;If not, you don't have HA, so think to add this laier to your architecture.&lt;/P&gt;&lt;P&gt;If yes it could be possible that it's the LB to distribute traffic in only one syslog server.&lt;/P&gt;&lt;P&gt;You can test this turning off one of them and verifying that the other continue to receive and forward all the syslogs.&lt;/P&gt;&lt;P&gt;Then how do you verified that only one server is sending its syslogs to the Indexer?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jul 2020 08:43:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-forwarding-data-with-HA/m-p/507393#M86344</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-07-05T08:43:51Z</dc:date>
    </item>
    <item>
      <title>Re: syslog forwarding data with HA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-forwarding-data-with-HA/m-p/507442#M86351</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;currently i am receiving data getting indexed from syslog1 server for 2 different sources/indexes.&lt;/P&gt;&lt;P&gt;But i am receiving data on syslog2 server for 1 source/index.&amp;nbsp;&lt;/P&gt;&lt;P&gt;and yes load balancer is there balancing in terms of volume.&amp;nbsp;&lt;/P&gt;&lt;P&gt;while we are investigating why 2nd source/index is not received on syslog2 server i need your help in understanding why in this scenario syslog1's data is not getting indexed for both source types.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 02:13:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-forwarding-data-with-HA/m-p/507442#M86351</guid>
      <dc:creator>surekhasplunk</dc:creator>
      <dc:date>2020-07-06T02:13:10Z</dc:date>
    </item>
    <item>
      <title>Re: syslog forwarding data with HA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-forwarding-data-with-HA/m-p/507463#M86355</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/193316"&gt;@surekhasplunk&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;as i said, probably is the Load Balancer that's sending logs to only one syslog server for one of the sources, check if your indexers is receiving all the logs and what happens if you turn off one of the syslog servers.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 05:33:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-forwarding-data-with-HA/m-p/507463#M86355</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-07-06T05:33:18Z</dc:date>
    </item>
    <item>
      <title>Re: syslog forwarding data with HA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-forwarding-data-with-HA/m-p/507508#M86370</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;In the indexer i am seeing below info without anything getting indexed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;07-06-2020 10:11:54.836 +0100 INFO CMSlave - event=setBucketSummaries bid=fgt~XXX~XXXXX update=fgt~XXX~XXXXXX&lt;BR /&gt;07-06-2020 10:11:54.836 +0100 INFO CMRepJob - running job=CMUpdateSummaries_AndRegisterSummariesSuccess updates=fgt~XXX~XXXXX&lt;/P&gt;&lt;P&gt;Not sure what this means&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 09:37:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-forwarding-data-with-HA/m-p/507508#M86370</guid>
      <dc:creator>surekhasplunk</dc:creator>
      <dc:date>2020-07-06T09:37:53Z</dc:date>
    </item>
    <item>
      <title>Re: syslog forwarding data with HA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-forwarding-data-with-HA/m-p/507509#M86371</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/193316"&gt;@surekhasplunk&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;in normal working, are you seeing all the logs or not?&lt;/P&gt;&lt;P&gt;did you tried to turn off one of the syslogs servers?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 09:40:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-forwarding-data-with-HA/m-p/507509#M86371</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-07-06T09:40:45Z</dc:date>
    </item>
  </channel>
</rss>

