Getting Data In

it's possible balnce an hec source?

aasabatini
Motivator

Hi Folks,

 

I have a question, I have 2 HF and I have to configure a hec source, I would balance the data across the two HF.

do you know the best pratices to do this?

Do i have to create the same inputs with the same token on both the HF and use a load balancer to do that?

 

Thanks in advance

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”
Labels (1)
0 Karma
1 Solution

PickleRick
Ultra Champion

Yes, that's exactly how you do it. You create a HEC input with the same settings (token, destination index/permitted indexes, maybe TLS settings if you're not offloading it to your LB). And you just place your LB in front of those HECs. Works like a charm 🙂

View solution in original post

PickleRick
Ultra Champion

Yes, that's exactly how you do it. You create a HEC input with the same settings (token, destination index/permitted indexes, maybe TLS settings if you're not offloading it to your LB). And you just place your LB in front of those HECs. Works like a charm 🙂

aasabatini
Motivator

Hi @PickleRick z, @gcusello ,

 

thanks for your confimation guys, just last question, do you know or exist some official documentation  about that? I mean the load balacing across the hec, no generic documentation.

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”
0 Karma

PickleRick
Ultra Champion

I'm not sure there is any as such. This is more about HTTP in general, it's not specific to HEC as such. It's exactly the same as with any load-balanced service. You probably can find some .conf presentation mentioning it or something or event training materials but I don't think it _needs_ a specific official documentation. HTTP is generally proxable so there is no reason why HEC shouldn't.

0 Karma

aasabatini
Motivator

Thanks @PickleRick 

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”
0 Karma

gcusello
Esteemed Legend

Ciao Alessandro,

yes, it's always better to use a Load Balancer to ingest syslogs: to distribute load during normal work and manage unavailability on one of them during fail over.

If you haven't a Load Balancer (always the best solution!) you could also use a DNS configuration, but it isn't so affidable because it takes some time to understand when an HF isn't available, so it looses some syslogs.

Then you configure on both the HFs the input with the same token.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Devesh Logendran, Splunk, and the Singapore Cyber Conquest

At this year’s Splunk University, I had the privilege of chatting with Devesh Logendran, one of the winners in ...

There's No Place Like Chrome and the Splunk Platform

WATCH NOW!Malware. Risky Extensions. Data Exfiltration. End-users are increasingly reliant on browsers to ...

Customer Experience | Join the Customer Advisory Board!

Are you ready to take your Splunk journey to the next level? 🚀 We invite you to join our elite squad ...