Hello!
I am trying to send syslogs to splunk from network devices using udp. I have one heavy forwarder and two indexers, does it matter which indexer i set up to listen for the data?
Hi @jmrubio ,
usually Heavy Forwarder are used to ingest syslogs.
Then your HF should forward data to both the Indexers.
Then you should also have a Search Head to search data on the two indexers.
Then usually, to avoid a Single Point of Failure, it's better to have two HFs with a Load Balancer in front of them that manages load distribution andfail over
Ciao.
Giuseppe
Hi @jmrubio ,
usually Heavy Forwarder are used to ingest syslogs.
Then your HF should forward data to both the Indexers.
Then you should also have a Search Head to search data on the two indexers.
Then usually, to avoid a Single Point of Failure, it's better to have two HFs with a Load Balancer in front of them that manages load distribution andfail over
Ciao.
Giuseppe
I have to work with what I have so it's going from the hf to the indexers. Thanks for the response @gcusello !!