Getting Data In

Can you help me with a question about persistent queuing with multiple tcp ports?

walkerhound
Path Finder

I have a forwarder that forwards to two different Splunk systems: SplunkA and SplunkB. The data coming into the forwarder is TCP data on two different ports, port A and port B. All data on port A is forwarded to SplunkA and all data on port B is forwarded to SplunkB.

I configured persistent queuing on both ports.

Then I shutdown SplunkA. I found that both both port A and port B data was queued. That means that none of the TCP data on port B was getting to SplunkB, even though SplunkB was up.

Is this expected behavior?

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...