Monitoring Splunk

Need advice about missing Forwarders in Splunk. What planning or DR measures do I take to make sure data is not lost?

SamHTexas
Builder

We have Network outages at times that make the FWs not available. I know that data can get quede up. But what if the outages is long & what does one do to make sure the SOC & IR have the latest data & events to work with? 

Labels (1)
Tags (1)
0 Karma

impurush
Contributor

Hi @SamHTexas,

As per my knowledge, if the data is from the file, then you no need to worry about the queue, Splunk will read from where it stopped. However, if the data is not from the file and it is generated data, then you need to increase the queue size to make the storage available to catch all the data during the forwarder offline.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...