Getting Data In

Palo Alto and Splunk - queue for outage period ?

GaetanVP
Contributor

Hello Splunkers,

I am using the official "Palo Alto Networks Add-on for Splunk" in order to ingest Palo logs inside my Splunk infra.

My path is basically Panorama --> HF --> Indexers.

I am wondering what will happen if my HF goes down during a certain amount of time ? Does the Panorama instance have a temporary outputs queue that will prevent data loss ? What could I do to make this flow of log more "resilient" ?

Thanks a lot,

GaetanVP

 

Labels (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

every time when you are using syslog to send data to splunk, the preferred method is use some real syslog server (cluster) to avoid lost events. Splunk HF's tcp input is not this kind of server!!

You should use your current syslog server to collect events or if you haven't anyone then set up e.g. SC4S (syslog connect for splunk) to manage syslog feed.

r. Ismo

GaetanVP
Contributor

Hello @isoutamo, thanks for you answer

Okay so you would suggest me to implement those two possibilities :

  • Palo Alto --> Syslog Server with UF installed --> HF --> Indexers (1)
  • Palo Alto --> HF with SC4S --> Indexers (2)

I do not really understand how those architectures can prevent data loss in case of a crash of the Syslog Server (1) or my HF (2). None of the servers will ask Palo to "resend" some data missed, or am I wrong ? 

Thanks,

GaetanVP

0 Karma

isoutamo
SplunkTrust
SplunkTrust

The second is just SC4S which doesn’t contains HF. It receive events via syslog server and sends those via HEC. 
When I said syslog server I actually means ha version if possible. That with LB can give you quite good service level. Also pure single node syslog server has much shorter restart/reload time. Based on that you have much better service level with these than you have with individual HF with TCT/UDP listener. 

Wihout LB you cannot avoid data loss with tcp protocol (this needs correctly configured LB, depends by product). If you are using UDP, then you will lose events (“feature” of protocol).

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...