Our set up-
HF receives syslog (directly from firewalls, IPS, etc) and logs from UF (windows and linux machines) and then forwards to Indexers, clustered and then to 2 search heads.
If the HF goes offline ( for few hours or a day), because of hardware or network issue. What will happen to the syslog data forwarded from firewalls to HF during that time, will it be lost? will the data from UF also be lost?
What is recommended to avoid any data loss during this period? Is there a need to modify the existing deployment?
Thanks in Advance
... View more