Deployment Architecture

Deployment Client Sending Logs to Backup Log Collector

daniaabujuma
Explorer

Hello,

I have a question regarding forwarding and receiving in Splunk. Can I configure the deployment client to send logs to another log collector in case the first one is not responding or receiving logs? To be more specific, is there any kind of configuration that can be done so the deployment client will automatically switch to another log collector if the first one isn't available?

Thank you.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

You are using "weird" terminology for Splunk. So I made some assumptions for those 😉

  • Deployment Client is usually called UF / forwarder.
  • Log Collector is indexer / search peer

You could add several indexer on outputs.conf and then UF can use all of those. But there is no automatic process how it can normally send to one indexer and if it's down then switch to another and go back when 1st will be back in the business.

When you have configured only one indexer in outputs.conf then if it's down then UF just stop sending data to it and wait until it will be back.

If/when you want to HA solution for receiving logs you should setup multiple individual indexers or even better to set up indexer cluster. See more about https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Aboutclusters

My personal opinion is that when you are setting up distributed environment, you should always set up also indexer cluster. If you have only few GBs per day ingested events, you could set up "single node cluster" and when your indexing amount will increase then it's really easy just to add additional nodes to that cluster.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...