Getting Data In

How to set up a high available syslog drain for cloud foundry to Splunk?

sgp0637
Engager

We have a cloud foundry set up and wants to forward the logs to splunk as syslog drain. The TCP/UDP input method is not ideal since the restart of the index will cause loss of data.

Moreover, the need for change in inputs.conf will be more often (planning to create the data forwarding on demand basis from different clients) which in turn will cause multiple restart of the indexer as well.

We are running an indexer cluster and a rolling restart is possible but again a load-balancer and a re-configuration of same is needed to communicate to load balancer not to send any data to the indexer which is being restarted. [ load balancer is needed here since there are no forwarders involved]

To have a separate syslong-ng or a forwarder is also not an option since its adding more components and complicating high availability set up

If you have done any HA set up for cloud foundry - splunk integration, please share .

Thank you!

Tags (2)
0 Karma
1 Solution

rarsan_splunk
Splunk Employee
Splunk Employee

Take a look at the recently released Splunk Firehose Nozzle for Cloud Foundry.
It's an HA setup to stream logs & metrics from Cloud Foundry Firehose to your Splunk deployment in a scalable, reliable and secure fashion. There's also a supporting Add-on to help visualize the data. More details here:
https://github.com/splunk/splunk-addon-for-cloud-foundry

View solution in original post

0 Karma

rarsan_splunk
Splunk Employee
Splunk Employee

Take a look at the recently released Splunk Firehose Nozzle for Cloud Foundry.
It's an HA setup to stream logs & metrics from Cloud Foundry Firehose to your Splunk deployment in a scalable, reliable and secure fashion. There's also a supporting Add-on to help visualize the data. More details here:
https://github.com/splunk/splunk-addon-for-cloud-foundry

0 Karma

sgp0637
Engager

Finally!!!. Thanks @rarsan_splunk .

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...