Getting Data In

Palo Alto and Splunk - queue for outage period ?

GaetanVP
Contributor

Hello Splunkers,

I am using the official "Palo Alto Networks Add-on for Splunk" in order to ingest Palo logs inside my Splunk infra.

My path is basically Panorama --> HF --> Indexers.

I am wondering what will happen if my HF goes down during a certain amount of time ? Does the Panorama instance have a temporary outputs queue that will prevent data loss ? What could I do to make this flow of log more "resilient" ?

Thanks a lot,

GaetanVP

 

Labels (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

every time when you are using syslog to send data to splunk, the preferred method is use some real syslog server (cluster) to avoid lost events. Splunk HF's tcp input is not this kind of server!!

You should use your current syslog server to collect events or if you haven't anyone then set up e.g. SC4S (syslog connect for splunk) to manage syslog feed.

r. Ismo

GaetanVP
Contributor

Hello @isoutamo, thanks for you answer

Okay so you would suggest me to implement those two possibilities :

  • Palo Alto --> Syslog Server with UF installed --> HF --> Indexers (1)
  • Palo Alto --> HF with SC4S --> Indexers (2)

I do not really understand how those architectures can prevent data loss in case of a crash of the Syslog Server (1) or my HF (2). None of the servers will ask Palo to "resend" some data missed, or am I wrong ? 

Thanks,

GaetanVP

0 Karma

isoutamo
SplunkTrust
SplunkTrust

The second is just SC4S which doesn’t contains HF. It receive events via syslog server and sends those via HEC. 
When I said syslog server I actually means ha version if possible. That with LB can give you quite good service level. Also pure single node syslog server has much shorter restart/reload time. Based on that you have much better service level with these than you have with individual HF with TCT/UDP listener. 

Wihout LB you cannot avoid data loss with tcp protocol (this needs correctly configured LB, depends by product). If you are using UDP, then you will lose events (“feature” of protocol).

0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...