Deployment Architecture

log collect mode

wangmang
Engager

which mode does  the splunk  forwarder support  ? If  push or pull mode is all supported, we want to know how to configure   the different mode,and  the  disadvantage and  between them?

Thanks

Labels (2)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @wangmang,

Universal Forwarders immediately send their logs to the Indexers if there's a connection with them.

Indexer only answers to the connection so the only configurable mode is push.

If there isn't any connection, the UF caches its logs until the connection is again available.

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @wangmang,

Universal Forwarders immediately send their logs to the Indexers if there's a connection with them.

Indexer only answers to the connection so the only configurable mode is push.

If there isn't any connection, the UF caches its logs until the connection is again available.

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @wangmang,

good for you, see next time!

Ciao and happy splunking.

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Get Updates on the Splunk Community!

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...