3 ms·
There would be usually multiple syslog sink servers so there is never a single point of failure. This can be configured in various ways either dns round robin,
by fluential 6y ago
There would be usually multiple syslog sink servers so there is never a single point of failure. This can be configured in various ways either dns round robin, load balancers or even multiple destinations configured on the client side, rsyslog can iterate over a list in case of failures.
If there is log storm coming from misconfigured app depending on your traffic levels the sink servers should give you a lot of space for an on-call engineer to be notified that something is off and adjust / rate limit / drop accordingly.
Edit: udated with more info