Getting Data In

VCS Cluster and Splunk

_gkollias
Builder

Hi Splunk,

I have a series of hosts that have been built on (VCS) HA clusters, and I'd like to get them forwarded in to Splunk,

Is it best practices to remove them from the cluster and have them built locally? The main concern I have is if /splunk fails over to its failover node.

I'm hoping one might know the best practice in this situation.

Thank you!

Tags (2)
1 Solution

jtrucks
Splunk Employee
Splunk Employee

Based on my previous experience with VCS and recent experience with Splunk, I would put each host's Splunk install into a different directory so they can run separately, OR I would exempt Splunk from failover as a service and have each host run it's own local forwarder. This way if services fail over, you continue to get logs from the right places with the right underlying hostname correct for the machine sending logs.

--
Jesse Trucks
Minister of Magic

View solution in original post

jtrucks
Splunk Employee
Splunk Employee

Based on my previous experience with VCS and recent experience with Splunk, I would put each host's Splunk install into a different directory so they can run separately, OR I would exempt Splunk from failover as a service and have each host run it's own local forwarder. This way if services fail over, you continue to get logs from the right places with the right underlying hostname correct for the machine sending logs.

--
Jesse Trucks
Minister of Magic

_gkollias
Builder

Thank you!

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...