Getting Data In

Splunk - Windows Network Load Balancing

gdavid
Path Finder

I currently only have a single splunk server, but i would like to break it out to a distributed setup. I have been wondering how to setup the network devices to forward syslog to a load balanced IP, so i dont lose any data during reboots etc. The easiest quickest way for me is windows network load balance. Does anyone else have experience with a setup like this?

is there a way to forward to 2 splunk servers and have it figure out that it's duplicate data and store only once?

0 Karma

StylusPilot
New Member

How did you go with this?

I'm looking for documentation on the same thing.

0 Karma

gdavid
Path Finder

no answers on this, i also have not had a chance to try it out yet.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...