- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk Universal Forwarder Connection to Indexer
ezajac
Path Finder
10-25-2012
10:49 AM
How does the Splunk Universal Forwarder handle the condition when SPLUNK TCP is used as the communication method and the Splunk Indexer is down? (maintenance, someone disconnects the server, ...)
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

ChrisG

Splunk Employee
10-25-2012
11:30 AM
As bmacias84 mentions in the other post, if your indexer is down you will lose data, but with a forwarder you can enable the indexer acknowledgement feature. See Protect against loss of in-flight data in the Distributed Deployment Manual.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
bmacias84
Champion
10-25-2012
11:13 AM
@ezajac, It depend on your input and your configuration. Here are a couple of post that already cover HA with links to additional read material.
if-the-receiver-is-down-would-the-data-from-the-universal-forwarder-be-lost
splunk-disaster-recovery?
Hope this helps. Cheers.
