It is also possible to use Splunk instances to receive the syslog events directly, which then forward the forwarders to the Splunk indexers. This setup might look somewhat like the following diagram:
These interim Splunk forwarder processes can be configured with a large input buffer using the queueSize and persistentQueueSize settings in inputs.conf. Note that these interim forwarders cannot be light forwarders. There are a few advantages to this approach that I can think of:
- If these Splunk forwarder processes are in the data center with the device producing the events, the forwarder process will ...