Client is has a clustered Active-DR setup for their PROD application. At a given time, only one server (node) is active and mounted with common NFS share.
When application switches over to the other node, NFS share (File system mount point) is unmounted from active one and same is mounted on another node.
We have a requirement to configure the Splunk universal forwarder on both the nodes. We can ask the support team to manually stop/start the Splunk forwarder during migration (switch over).
However, not sure how Splunk universal forwarder will behave while reading (tailing) same log file from a different forwarder and indexing in the same index.
Please share your comments.
↧