After a Splunk restart or temporary network interruption, the FPolicy connection from ONTAP to the Splunk add-on is not automatically reestablished. As a result, event ingestion stops until manual intervention, which can lead to data loss.
Additionally, NetApp FPolicy Persistent Store requires support from the external receiver. It is currently unclear whether this add-on provides such support. Without it, event buffering and replay are not available.
Are there any plans to address these limitations or recommended workarounds?
After a Splunk restart or temporary network interruption, the FPolicy connection from ONTAP to the Splunk add-on is not automatically reestablished. As a result, event ingestion stops until manual intervention, which can lead to data loss.
Additionally, NetApp FPolicy Persistent Store requires support from the external receiver. It is currently unclear whether this add-on provides such support. Without it, event buffering and replay are not available.
Are there any plans to address these limitations or recommended workarounds?