All Apps and Add-ons

How will thousands of syslog events sent to Hadoop affect a heavy forwarder?

a212830
Champion

Hi,

I am currently processing syslog events, using the hfw. This feed is pretty busy - hundreds of files, and I'm being asked to forward all the data to Hadoop. How will this affect the forwarder? These events are critical within Splunk, and I don't want any delay to be added. I'm not sure of the need for real-time here, so my suggestion is going to be Hadoop Connect.

0 Karma

hsesterhenn_spl
Splunk Employee
Splunk Employee

Hi,

indexing the data using Splunk Enterprise Core in combination with a HFW should not be influenced if you export the data off the indexer using Hadoop Connect.

Remember, Hadoop Connect will run a search and then export the result/data to Hadoop.

Maybe the Hadoop Data Roll feature is a better option if you want to archive buckets instead of exporting files.

https://docs.splunk.com/Documentation/Splunk/latest/Indexer/ArchivingindexestoHadoop

HTH,

Holger

0 Karma

a212830
Champion

thousands of events...

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...