Monitoring Splunk

If lightweight forwarders are configured on laptops that are not always connected to a network, will it impact the client's performance?

Thomas_Aneiro
Explorer

Our desktop team is rolling out a new patch management service (Shavlik) which only sends a limited amount of logs to the central system. I wanted to see whether or not it would be managable to remotely configure lightweight forwarders on all the clients to send the logs through splunk. The only thing is many of these laptops do not connect to our network on a daily basis, either from being hard-wired or VPN. My concern is that if these devices are being used off network will the lightweight forwarder throw back errors because it cannot reach the heavy forwarder/indexes? Also, would this create excess logs in ESS via "Expected Host Not Reporting" incidents?

0 Karma
1 Solution

bmunson_splunk
Splunk Employee
Splunk Employee

No this will not be a problem. The forwarder gracefully stops and waits for the indexer to become available again. It will log that it can't get to the indexer but that isn't a problem.

In ES you can state which devices are expected and which are intermittent so as long as you set this correctly it will not complain. But one thing to be aware of is ES normally only looks at the last 24 hours for security issues. If splunk doesn't get the logs for longer, it may not be detected. You can probably adjust the corrolation searches to allow for this.

View solution in original post

bmunson_splunk
Splunk Employee
Splunk Employee

No this will not be a problem. The forwarder gracefully stops and waits for the indexer to become available again. It will log that it can't get to the indexer but that isn't a problem.

In ES you can state which devices are expected and which are intermittent so as long as you set this correctly it will not complain. But one thing to be aware of is ES normally only looks at the last 24 hours for security issues. If splunk doesn't get the logs for longer, it may not be detected. You can probably adjust the corrolation searches to allow for this.

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...