Refine your search:

I read somewhere that a Forwarder and Indexer can be configured to acknowledge the success of indexing an event, so as to enable retrys upon failure.Albeit a hit to performance.

Lets say, worst case scenario, even in a complex HA clustering of indexers, that ALL your indexers go down. In this scenario, do Universal Forwarders or Light Forwarders have the ability to buffer up raw event data until at least 1 indexer in the cluster comes up again ?

DD.

asked 26 Jul '11, 22:08

Damien%20Dallimore's gravatar image

Damien Dalli...
4.6k2313
accept rate: 23%

Be the first one to answer this question!
toggle preview

Follow this question

Log In to enable email subscriptions

RSS:

Answers

Answers + Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "Title")
  • image?![alt text](/path/img.jpg "Title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Tags:

×637
×24
×4
×1

Asked: 26 Jul '11, 22:08

Seen: 952 times

Last updated: 26 Jul '11, 22:08

Copyright © 2005-2012 Splunk Inc. All rights reserved.