Getting Data In

Splunk 2 Splunk SSL Persistent Queues

ephemeric
Contributor

Am I just missing something or being stupid or are there no persistent queues when using Splunk2Splunk with SSL?

I see indexer acknowledgement in 4.2.1 but how does one protect against loss of in flight data over SSL and how does one (if possible) spool to disk if the intermediate forwarder or indexer are down?

1 Solution

ephemeric
Contributor

As per the docs this is not supported in this configuration.

0 Karma
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf24, and Community Connections

Thank you to everyone in the Splunk Community who joined us for .conf24 – starting with Splunk University and ...

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...