All Apps and Add-ons

How will thousands of syslog events sent to Hadoop affect a heavy forwarder?

a212830
Champion

Hi,

I am currently processing syslog events, using the hfw. This feed is pretty busy - hundreds of files, and I'm being asked to forward all the data to Hadoop. How will this affect the forwarder? These events are critical within Splunk, and I don't want any delay to be added. I'm not sure of the need for real-time here, so my suggestion is going to be Hadoop Connect.

0 Karma

hsesterhenn_spl
Splunk Employee
Splunk Employee

Hi,

indexing the data using Splunk Enterprise Core in combination with a HFW should not be influenced if you export the data off the indexer using Hadoop Connect.

Remember, Hadoop Connect will run a search and then export the result/data to Hadoop.

Maybe the Hadoop Data Roll feature is a better option if you want to archive buckets instead of exporting files.

https://docs.splunk.com/Documentation/Splunk/latest/Indexer/ArchivingindexestoHadoop

HTH,

Holger

0 Karma

a212830
Champion

thousands of events...

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...