Getting Data In

Highly Available Forwarder?

garyewhite
Explorer

Anyone have highly available forwarders deployed? Looking for the 'best' solution.
Hate to drop logs during maintenance cycles, even if it's only 3-5 minutes worth...
Any suggestions appreciated.

0 Karma
1 Solution

garyewhite
Explorer

Going with a Baracuda 540.

View solution in original post

0 Karma

garyewhite
Explorer

Going with a Baracuda 540.

0 Karma

antlefebvre
Communicator

I would imagine a load balancer would be your best bet. If you have to perform maintenance to your forwarders if you do them one at a time the load balancer would see the device as down and send the traffic to an available forwarder.

0 Karma

garyewhite
Explorer

No load balancer, at the moment. Looking for suggestions on type: Hardware/Software, and possibly examples of live configs that work well.

0 Karma

antlefebvre
Communicator

Do you have a load balancer in your environment? If so, you just put the same forwarder config on 2 different machines. Point the firewalls at the balancer, balancer at the forwarders, and the forwarders will send the data to the indexers.

0 Karma

garyewhite
Explorer

I agree... but load balancing is easy when we're talking Indexers... I've done that. Load balancing the Forwarder(s) is uncharted territory, for me, though...
Anyone have a working, balanced, Forwarder config they can recommend?
Thanks!

0 Karma

rechteklebe
Path Finder

Why not saving the logs on a NAS and forwarding data from a dedicated silly VM?

0 Karma

garyewhite
Explorer

My firewalls are sending their logs to Forwarders. Can I either redirect them to a NAS when the Forwarders are rebooting or have the Forwarder access them from the NAS and make the NAS the default?
Not certain I understand...
Thx

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...