<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multi site  Data center forwarding data to indexer? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Multi-site-Data-center-forwarding-data-to-indexer/m-p/370268#M92872</link>
    <description>&lt;P&gt;Thanks for the response .&lt;BR /&gt;
 we are going to collect  all the logs with syslog-ng and UF and sending it to intermediate forwarder which in turn would send data to indexer .&lt;/P&gt;</description>
    <pubDate>Mon, 26 Jun 2017 00:04:20 GMT</pubDate>
    <dc:creator>aab5272</dc:creator>
    <dc:date>2017-06-26T00:04:20Z</dc:date>
    <item>
      <title>Multi site  Data center forwarding data to indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Multi-site-Data-center-forwarding-data-to-indexer/m-p/370265#M92869</link>
      <description>&lt;P&gt;Considering multi site data center for log forwarding having same logs  , lets say site 1 and site 2 logs are  being forwarded to indexer ,will this two copy will counted twice while indexing license if yes then what should be the approach to filter one copy of data before forwarding ?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2017 19:30:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Multi-site-Data-center-forwarding-data-to-indexer/m-p/370265#M92869</guid>
      <dc:creator>aab5272</dc:creator>
      <dc:date>2017-06-23T19:30:23Z</dc:date>
    </item>
    <item>
      <title>Re: Multi site  Data center forwarding data to indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Multi-site-Data-center-forwarding-data-to-indexer/m-p/370266#M92870</link>
      <description>&lt;P&gt;are you using Universal Forwarder to send these logs to Indexers? if yes, use autoLB and put names of all Indexers in the list to load balance, and the UF will work out where to send and it will send only one copy.&lt;/P&gt;

&lt;P&gt;if you let me know which mechanism is used to send the data, we can answer. cheers&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jun 2017 09:38:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Multi-site-Data-center-forwarding-data-to-indexer/m-p/370266#M92870</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2017-06-24T09:38:47Z</dc:date>
    </item>
    <item>
      <title>Re: Multi site  Data center forwarding data to indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Multi-site-Data-center-forwarding-data-to-indexer/m-p/370267#M92871</link>
      <description>&lt;P&gt;Any forwarder sending data into any Indexer will only be counted once.  If 2 servers are sending the same data (perhaps through an NFS cross mount), then you will get 2 copies of the data in splunk and each will count against the license.  If you have a multi-site cluster where splunk deliberately makes multiple copies internally (1 forwarder sends 1 copy to 1 Indexer, then SPLUNK makes copies all around), then you will only ever see/search 1 copy and it will only count against the license once.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Jun 2017 23:31:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Multi-site-Data-center-forwarding-data-to-indexer/m-p/370267#M92871</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-06-25T23:31:01Z</dc:date>
    </item>
    <item>
      <title>Re: Multi site  Data center forwarding data to indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Multi-site-Data-center-forwarding-data-to-indexer/m-p/370268#M92872</link>
      <description>&lt;P&gt;Thanks for the response .&lt;BR /&gt;
 we are going to collect  all the logs with syslog-ng and UF and sending it to intermediate forwarder which in turn would send data to indexer .&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2017 00:04:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Multi-site-Data-center-forwarding-data-to-indexer/m-p/370268#M92872</guid>
      <dc:creator>aab5272</dc:creator>
      <dc:date>2017-06-26T00:04:20Z</dc:date>
    </item>
  </channel>
</rss>

