<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal forwarder and Deployment Server in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Universal-forwarder-and-Deployment-Server/m-p/521449#M4481</link>
    <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;, sure, new question from next time on wards&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 25 Sep 2020 12:50:10 GMT</pubDate>
    <dc:creator>hectorvp</dc:creator>
    <dc:date>2020-09-25T12:50:10Z</dc:date>
    <item>
      <title>Universal forwarder and Deployment Server</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Universal-forwarder-and-Deployment-Server/m-p/521100#M4473</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I've a scenario where our organisation is supposed to only send logs from servers to clients indexers.&lt;/P&gt;&lt;P&gt;We have decided to use UF and deployment server.&lt;/P&gt;&lt;P&gt;We need to know what are known downtimes, performance issues&amp;nbsp; for for UFs and deployment servers.&lt;/P&gt;&lt;P&gt;For example incase there may be any downtime while upgrade of UFs or any maintenance aspects.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there any exceptions with capabilities of UF to forward logs like for certain application (commonly used) logs cannot be forwarded since they are in xyz format.....&lt;/P&gt;&lt;P&gt;For example incase there may be any downtime while upgrade of UF.&lt;/P&gt;&lt;P&gt;We need this information for certain agreements with the customer.&lt;/P&gt;&lt;P&gt;Can anyone enlist few points here.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2020 15:45:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Universal-forwarder-and-Deployment-Server/m-p/521100#M4473</guid>
      <dc:creator>hectorvp</dc:creator>
      <dc:date>2020-09-23T15:45:38Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder and Deployment Server</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Universal-forwarder-and-Deployment-Server/m-p/521104#M4474</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223614"&gt;@hectorvp&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;forwarders is the best approach to take logs from servers because UF guarantee to you some feature improvement than other methods (e.g. WMI or syslogs), these are the main:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;packets are compressed so you consume less bandwidth,&lt;/LI&gt;&lt;LI&gt;UFs has a local cache for logs in case of unavailability of Indexers;&lt;/LI&gt;&lt;LI&gt;it's possible to configure packets dimension to limit the&amp;nbsp;bandwidth.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;UFs cosumes just a little part of server resources (e.g.: on it uses around Windows 70-80 MB RAM and 2-3 % of CPU usage).&lt;/P&gt;&lt;P&gt;Deployment Server is the best approach to manage UFs.&lt;/P&gt;&lt;P&gt;UFs continue to work also with the DS down, so it isn't a Single Point of Failure.&lt;/P&gt;&lt;P&gt;Downtime isn't relevant because installation, upgrade of UF or configurations don't require a server restart.&lt;/P&gt;&lt;P&gt;DS must be a dedicated machine if it has to manage more than 50 clients.&lt;/P&gt;&lt;P&gt;DS can also be a virtual server, but it needs of the same resources of a stand-alone Splunk (12 CPUs and 12 GB of RAM).&lt;/P&gt;&lt;P&gt;Here you can find all the documentation about DS &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.6/Updating/Aboutdeploymentserver" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.6/Updating/Aboutdeploymentserver&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2020 15:59:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Universal-forwarder-and-Deployment-Server/m-p/521104#M4474</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-09-23T15:59:44Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder and Deployment Server</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Universal-forwarder-and-Deployment-Server/m-p/521118#M4475</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thanks again for the response.&lt;/P&gt;&lt;P&gt;Can I expect uptime of 99.99% ? (Considering UFs and DS are properly configured)&lt;/P&gt;&lt;P&gt;Is there any situation where agent may crash and need to take a look??&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example if clients indexers aren't receiving any logs.&lt;/P&gt;&lt;P&gt;From ur above response I consider there won't be any downtime with UF maintenance.&lt;/P&gt;&lt;P&gt;But still would there be any data loss while upgrading UF?&lt;/P&gt;&lt;P&gt;And the last one&lt;/P&gt;&lt;P&gt;Are there any exceptions where UFs cannot pick logs from server (ex: not supported any file extensions like etl ). I'm afraid of with application logs mostly since they may not have been logging data as windows event logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2020 16:54:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Universal-forwarder-and-Deployment-Server/m-p/521118#M4475</guid>
      <dc:creator>hectorvp</dc:creator>
      <dc:date>2020-09-23T16:54:48Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder and Deployment Server</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Universal-forwarder-and-Deployment-Server/m-p/521218#M4476</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223614"&gt;@hectorvp&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;answering to your questions:&lt;/P&gt;&lt;P&gt;1)&lt;/P&gt;&lt;P&gt;uptime depends on the maintenance you schedule for your systems, as I said, Splunk doesn't require server restart;&lt;/P&gt;&lt;P&gt;if you're speking of monitoring uptime, Splunk doesn't lose any log because it cashes logs when cannot send them to Indexers.&lt;/P&gt;&lt;P&gt;2)&lt;/P&gt;&lt;P&gt;In my experience I saw agent crashes only on some Windows server (especially if they didn't have sufficient resources), when it happened I opened a case to Splunk Support.&lt;/P&gt;&lt;P&gt;3)&lt;/P&gt;&lt;P&gt;if Indexers don't receive logs, you have to configure an alert to notice this event and immediately intervene (I usually configure an alert triggering every 5 minutes).&lt;/P&gt;&lt;P&gt;4)&lt;/P&gt;&lt;P&gt;as I said you don't lose logs during maintenance.&lt;/P&gt;&lt;P&gt;The only logs you risk to lose are syslogs because you have to ingest them when they arrive, for this reason I hint to use two Heavy Forwarders with a Load Balancer, in this way you put in maintenance only one at a time of them.&lt;/P&gt;&lt;P&gt;5)&lt;/P&gt;&lt;P&gt;when you upgrade UFs, they obviously don't send logs but they send them as soon as they are connected.&amp;nbsp;&lt;/P&gt;&lt;P&gt;6)&lt;/P&gt;&lt;P&gt;Splunk takes avery kind of text logs and some special logs as wineventlogs, to know which logs Splunk can index see at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/8.1.2008/Data/WhatSplunkcanmonitor#What_data_can_I_index?" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/8.1.2008/Data/WhatSplunkcanmonitor#What_data_can_I_index?&lt;/A&gt;&lt;/P&gt;&lt;P&gt;for other kind of data, see in splunkbase (apps.splunk.com) if there's a special Technical Add-Ons (TA), otherwise, you have to preparse them before indexing by script (e.g. encrypted data).&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2020 07:30:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Universal-forwarder-and-Deployment-Server/m-p/521218#M4476</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-09-24T07:30:56Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder and Deployment Server</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Universal-forwarder-and-Deployment-Server/m-p/521433#M4479</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Just one follow up question&lt;/P&gt;&lt;P&gt;Since we have a task only to forward OS and application logs from servers to the customers indexer, we only meed Splunk Core license, right?&lt;/P&gt;&lt;P&gt;Or is there any possibility that any other license for example ITSI would be needed?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 11:22:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Universal-forwarder-and-Deployment-Server/m-p/521433#M4479</guid>
      <dc:creator>hectorvp</dc:creator>
      <dc:date>2020-09-25T11:22:12Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder and Deployment Server</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Universal-forwarder-and-Deployment-Server/m-p/521435#M4480</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223614"&gt;@hectorvp&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;this is another question and, for the future, it should be better to open a new question!&lt;/P&gt;&lt;P&gt;Anyway, Splunk licensing is related only to the daily indexed logs, not other thing as number of forwarders, Splunk servers, installed apps, etc...&lt;/P&gt;&lt;P&gt;The only exception are premium apps (like ITSI or ES) that you have to pay in addition to the Splunk Enterprise license.&lt;/P&gt;&lt;P&gt;Also ITSI and ES licenses are measured using the daily log volume .&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 13:17:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Universal-forwarder-and-Deployment-Server/m-p/521435#M4480</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-09-25T13:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder and Deployment Server</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Universal-forwarder-and-Deployment-Server/m-p/521449#M4481</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;, sure, new question from next time on wards&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 12:50:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Universal-forwarder-and-Deployment-Server/m-p/521449#M4481</guid>
      <dc:creator>hectorvp</dc:creator>
      <dc:date>2020-09-25T12:50:10Z</dc:date>
    </item>
  </channel>
</rss>

