Getting Data In

What is the backup plan for Splunk HTTP Event Collector implementation if indexers have issues?

abhi04
Communicator

Hi All,

Can you please let me know what approach and steps would be in case the Splunk HEC implementation on indexers runs into some issues?

This also includes getting syslog data from syslog-ng servers into indexers using HEC.

Labels (2)
0 Karma

maraman_splunk
Splunk Employee
Splunk Employee

You can use useack functionality with HEC if you want.
See opensourced hec client
If all indexers are down or not available, the source should stop sending and either queue or propagate the issue down the chain (ie to stop eating new data).
For Syslog, Splunk Connect for Syslog has this functionality for example, see disk buffer here

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...