Environment
Splunk Enterprise 9.3.3
Indexer Cluster (3 Indexers)
Universal Forwarders
Questions
①During a complete shutdown of all Indexers, are there any limitations on the amount of data or retention period for data buffered on the Universal Forwarders? ★
②If all Indexers remain unavailable for approximately three weeks, is there a risk that the Universal Forwarders may be unable to retain all pending data, resulting in data loss? ★
③After the Indexers are restored, what is the recommended procedure for resending any queued or unsent data from the Universal Forwarders?
④Are there any recommended best practices or maintenance procedures when shutting down and subsequently restarting all Indexers in an Indexer Cluster?
Questions marked with a ★ are priorities for our company. If possible, we would appreciate it if you could address these points first.