Deployment Architecture

log collect mode

wangmang
Engager

which mode does  the splunk  forwarder support  ? If  push or pull mode is all supported, we want to know how to configure   the different mode,and  the  disadvantage and  between them?

Thanks

Labels (2)
0 Karma
1 Solution

gcusello
Legend

Hi @wangmang,

Universal Forwarders immediately send their logs to the Indexers if there's a connection with them.

Indexer only answers to the connection so the only configurable mode is push.

If there isn't any connection, the UF caches its logs until the connection is again available.

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
Legend

Hi @wangmang,

Universal Forwarders immediately send their logs to the Indexers if there's a connection with them.

Indexer only answers to the connection so the only configurable mode is push.

If there isn't any connection, the UF caches its logs until the connection is again available.

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
Legend

Hi @wangmang,

good for you, see next time!

Ciao and happy splunking.

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!