|
I read somewhere that a Forwarder and Indexer can be configured to acknowledge the success of indexing an event, so as to enable retrys upon failure.Albeit a hit to performance. Lets say, worst case scenario, even in a complex HA clustering of indexers, that ALL your indexers go down. In this scenario, do Universal Forwarders or Light Forwarders have the ability to buffer up raw event data until at least 1 indexer in the cluster comes up again ? DD. |