Getting Data In

How to set up a high available syslog drain for cloud foundry to Splunk?

sgp0637
Engager

We have a cloud foundry set up and wants to forward the logs to splunk as syslog drain. The TCP/UDP input method is not ideal since the restart of the index will cause loss of data.

Moreover, the need for change in inputs.conf will be more often (planning to create the data forwarding on demand basis from different clients) which in turn will cause multiple restart of the indexer as well.

We are running an indexer cluster and a rolling restart is possible but again a load-balancer and a re-configuration of same is needed to communicate to load balancer not to send any data to the indexer which is being restarted. [ load balancer is needed here since there are no forwarders involved]

To have a separate syslong-ng or a forwarder is also not an option since its adding more components and complicating high availability set up

If you have done any HA set up for cloud foundry - splunk integration, please share .

Thank you!

Tags (2)
0 Karma
1 Solution

rarsan_splunk
Splunk Employee
Splunk Employee

Take a look at the recently released Splunk Firehose Nozzle for Cloud Foundry.
It's an HA setup to stream logs & metrics from Cloud Foundry Firehose to your Splunk deployment in a scalable, reliable and secure fashion. There's also a supporting Add-on to help visualize the data. More details here:
https://github.com/splunk/splunk-addon-for-cloud-foundry

View solution in original post

0 Karma

rarsan_splunk
Splunk Employee
Splunk Employee

Take a look at the recently released Splunk Firehose Nozzle for Cloud Foundry.
It's an HA setup to stream logs & metrics from Cloud Foundry Firehose to your Splunk deployment in a scalable, reliable and secure fashion. There's also a supporting Add-on to help visualize the data. More details here:
https://github.com/splunk/splunk-addon-for-cloud-foundry

0 Karma

sgp0637
Engager

Finally!!!. Thanks @rarsan_splunk .

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...