Hey everyone, quick UF question here... If a UF stops for whatever reason then comes back on later on, will the UF send the backlogs it missed while the service went offline?
Hi @johann2017,
yes: if connection with Indexer is interrupted, UF locally caches logs and send them as soon as connection is restored.
If it's the UF itself to stop, when it restarts it ingest all the logs from the last ingested.
There's only one situation when logs are lost and it's when I use an Heavy Forwarder to ingest syslogs but it's out of scope of your question.
Ciao.
Giuseppe
Yes, UFs will pick up where they left off.
Thank you rich!
Hi @johann2017,
yes: if connection with Indexer is interrupted, UF locally caches logs and send them as soon as connection is restored.
If it's the UF itself to stop, when it restarts it ingest all the logs from the last ingested.
There's only one situation when logs are lost and it's when I use an Heavy Forwarder to ingest syslogs but it's out of scope of your question.
Ciao.
Giuseppe