Getting Data In

Universal Forwarder as buffer only

jstockt
New Member

If the intention of using a Universal Forwarder is only for a buffer to the Indexer, is it worth having one?
Theory: Should there be a need to take the Indexer down for maintenance, the UF could continue to receive data and then catch the Indexer back up when maintenance is complete.
Is there any other method (outside of maybe Clustered Indexer) to ensure that log data continues to flow (from say 300 inputs) to somewhere while the Indexer server is down for a short period?

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The Universal Forwarder is more than just a buffer. Without it, how would you monitor the logs on remote (to Splunk) systems?

Another method to ensure data flows while an indexer is down for service is to have multiple indexers. If the UF is configured to forward to all indexers (and it should) then it will have an alternative path if one indexer is down. In the normal case, your data will be distributed across several indexers for better search performance.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The Universal Forwarder is more than just a buffer. Without it, how would you monitor the logs on remote (to Splunk) systems?

Another method to ensure data flows while an indexer is down for service is to have multiple indexers. If the UF is configured to forward to all indexers (and it should) then it will have an alternative path if one indexer is down. In the normal case, your data will be distributed across several indexers for better search performance.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...