Getting Data In

Is it possible to have fail-over rather than load balancing on to heavy forwarders?

luhadia_aditya
Path Finder

While architecting the splunk implementation we are caught up in to a scenario wherein we are trying to achieve fail-over, high availability configuration on to Heavy Forwarders. The requirement goes as -

We have 2 heavy forwarders (currently only one in use) on which data is written in to the log files using syslog-ng, further those log files are being monitored by Heavy Forwarders, note here that syslog-ng and heavy forwarder reside on the same instance. This particular instance actually listens on to a network port and then syslog-ng filters and writes that data to specific log files.

Now we would want to have the other heavy forwarder to act as a secondary instance, and if the primary (or first) heavy forwarder goes down then secondary heavy forwarder should start receiving data automatically.

We are not looking forward to have auto load balancing in which data would be forwarded to both the heavy forwarders simultaneously and if one goes down, other is still on duty. No. As stated we want fail over rather than auto LB.

Is this achievable ?
Any help, configurations, ideas, links, pointers are appreciable!
Thanks everyone.

0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi luhadia_aditya,

This is not related to Splunk. You need to setup this outside Splunk by using some other technique like F5 Network devices or DNS alias or Linux Heartbeat. Check Dr. Google there are tons of article related to syslog and fail-over / load-balancing setups.

cheers, MuS

View solution in original post

MuS
SplunkTrust
SplunkTrust

Hi luhadia_aditya,

This is not related to Splunk. You need to setup this outside Splunk by using some other technique like F5 Network devices or DNS alias or Linux Heartbeat. Check Dr. Google there are tons of article related to syslog and fail-over / load-balancing setups.

cheers, MuS

luhadia_aditya
Path Finder

Thanks MuS!! Appreciate your quick response.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...