Hi ,
We have configured a couple of Bluecoats on TCP custom ports on a HF. i see the data flowing in but the Bluecoat admins frequently comment that they are receiving alerts for failed upload to Splunk.
My 1st guess is that the port is exceeding the buffer limit or has filled up its queue.
But how can I ensure there is no data loss? Can we enable multiple listeners on a HF? We are to onboard more Bluecoats to Splunk through the same HF. Is there a limit to the number of listeners we can configure on a HF?
Does it affect performance?
Thanks,
Shiv
↧