Deployment Architecture

In Splunk, is there a way to have a cluster of forwarders (heavy or universal) ?

tdanielou
New Member

Hello,

Is there a way to have a cluster of forwarders (heavy or universal) ?

We have multiple sources that send the same data to the indexer cluster, so we have X time the same data.
If we could have an active/passive cluster of forwarders, we could have only one time the data and the warranty that we always have the data on Splunk.

thx.

Tags (2)
0 Karma

ddrillic
Ultra Champion

@tdanielou, the best practice is to rely on the universal forwarder file systems as the caching backup whereas for heavy forwarders to use a set of them behind a load balancer, to ensure 100% availability.

0 Karma

bjoernjensen
Contributor

Hey,

for what reason do you have one source multiple times? If that is due to compliance, stageing or data governance requirements you might have to go the hard way and install redundant storage instances (indexes).

If your architectures guarantees that all sources are the same at all time ... you just need to ingest one.

If splunk is used to verify that all sources contain exactly the same data you are free to choose for your source files. Put each in a separate index peer or index, or all in one and a scheduled search on top of that.

Hope that helps!
Björn

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...