Deployment Architecture

log collect mode

wangmang
Engager

which mode does  the splunk  forwarder support  ? If  push or pull mode is all supported, we want to know how to configure   the different mode,and  the  disadvantage and  between them?

Thanks

Labels (2)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @wangmang,

Universal Forwarders immediately send their logs to the Indexers if there's a connection with them.

Indexer only answers to the connection so the only configurable mode is push.

If there isn't any connection, the UF caches its logs until the connection is again available.

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @wangmang,

Universal Forwarders immediately send their logs to the Indexers if there's a connection with them.

Indexer only answers to the connection so the only configurable mode is push.

If there isn't any connection, the UF caches its logs until the connection is again available.

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @wangmang,

good for you, see next time!

Ciao and happy splunking.

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...