Hi all, I'm new to this forum and found quite a few ideas and solutions to issues admins hit. The organisation I work for are standing up a new site and requested new pair of heavy forwarders to be installed. The issue we have been mulling over is how to provide a highly available forwarder cluster at this site. The forwarders will be based on Linux, will process data from the network (Syslog, netflows etc) and also process files located on a NFS share (service provider managed CIFS/NFS share). We are using Splunk Cloud but have a deployment server on-prem to manage forwarders on the internal networks. My question - is there a solution to provide a clustered pair of forwarders that act in an active/passive cluster that allows support for processing files and also accepting network traffic? cheers aiders
... View more