Getting Data In

How to set up a high available syslog drain for cloud foundry to Splunk?

sgp0637
Engager

We have a cloud foundry set up and wants to forward the logs to splunk as syslog drain. The TCP/UDP input method is not ideal since the restart of the index will cause loss of data.

Moreover, the need for change in inputs.conf will be more often (planning to create the data forwarding on demand basis from different clients) which in turn will cause multiple restart of the indexer as well.

We are running an indexer cluster and a rolling restart is possible but again a load-balancer and a re-configuration of same is needed to communicate to load balancer not to send any data to the indexer which is being restarted. [ load balancer is needed here since there are no forwarders involved]

To have a separate syslong-ng or a forwarder is also not an option since its adding more components and complicating high availability set up

If you have done any HA set up for cloud foundry - splunk integration, please share .

Thank you!

Tags (2)
0 Karma
1 Solution

rarsan_splunk
Splunk Employee
Splunk Employee

Take a look at the recently released Splunk Firehose Nozzle for Cloud Foundry.
It's an HA setup to stream logs & metrics from Cloud Foundry Firehose to your Splunk deployment in a scalable, reliable and secure fashion. There's also a supporting Add-on to help visualize the data. More details here:
https://github.com/splunk/splunk-addon-for-cloud-foundry

View solution in original post

0 Karma

rarsan_splunk
Splunk Employee
Splunk Employee

Take a look at the recently released Splunk Firehose Nozzle for Cloud Foundry.
It's an HA setup to stream logs & metrics from Cloud Foundry Firehose to your Splunk deployment in a scalable, reliable and secure fashion. There's also a supporting Add-on to help visualize the data. More details here:
https://github.com/splunk/splunk-addon-for-cloud-foundry

0 Karma

sgp0637
Engager

Finally!!!. Thanks @rarsan_splunk .

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...