I am trying to setup a pair of VCS servers and would like to push the engine_A.log to our production Splunk servers, but I want to send it to a DNS name in order to utilize our VIP. Without using the VIP I am tied to using an IP. What happens when that IP goes down? We lose logs. I could probably send to both our production Splunk servers, but then I would have duplicate entries.
Is there a way around setting up Distrubuted / Data Forwarding to use a DNS entry versus an IP?
Regards.