2 heavy forwarders are configured to receive syslog inputs on port UDP / TCP 1600.Linux servers are configured to send the logs on a single dns entry instead of an IP address.The dns entry has been configured using DNS round robin and has the IP's of the 2 heavy forwarders. This is to achieve load balancing and in case if one of the HF fails the dns entry will try the second HF to send the logs.
But this doesn't work in the Rsyslog deamon for Linux as it doesn't attempt for the next HF .If one HF fails it doesn't reach out to the 2nd HF listed in the dns entry as a result the logs are not forwarded in spite of having 2 HF's configured with DNS round robin.
Need advice on this please and if there is a workaround.
We are going agentless for unix servers.
↧