Getting Data In

Highly Available Forwarder?

garyewhite
Explorer

Anyone have highly available forwarders deployed? Looking for the 'best' solution.
Hate to drop logs during maintenance cycles, even if it's only 3-5 minutes worth...
Any suggestions appreciated.

0 Karma
1 Solution

garyewhite
Explorer

Going with a Baracuda 540.

View solution in original post

0 Karma

garyewhite
Explorer

Going with a Baracuda 540.

0 Karma

antlefebvre
Communicator

I would imagine a load balancer would be your best bet. If you have to perform maintenance to your forwarders if you do them one at a time the load balancer would see the device as down and send the traffic to an available forwarder.

0 Karma

garyewhite
Explorer

No load balancer, at the moment. Looking for suggestions on type: Hardware/Software, and possibly examples of live configs that work well.

0 Karma

antlefebvre
Communicator

Do you have a load balancer in your environment? If so, you just put the same forwarder config on 2 different machines. Point the firewalls at the balancer, balancer at the forwarders, and the forwarders will send the data to the indexers.

0 Karma

garyewhite
Explorer

I agree... but load balancing is easy when we're talking Indexers... I've done that. Load balancing the Forwarder(s) is uncharted territory, for me, though...
Anyone have a working, balanced, Forwarder config they can recommend?
Thanks!

0 Karma

rechteklebe
Path Finder

Why not saving the logs on a NAS and forwarding data from a dedicated silly VM?

0 Karma

garyewhite
Explorer

My firewalls are sending their logs to Forwarders. Can I either redirect them to a NAS when the Forwarders are rebooting or have the Forwarder access them from the NAS and make the NAS the default?
Not certain I understand...
Thx

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...