Log pipeline
UniFi network gear and app logs land in Splunk via Cribl Edge. HAProxy fronts the Cribl Edge cluster for high availability. Coral dashed edges carry the data; the solid green edge is the physical syslog hop. Cribl Edge drops verbose fields, routes byevent_type, and enriches and masks the rest. The indexer takes a smaller,
cleaner payload.
NetFlow pipeline
NetFlow v9 / IPFIX from network devices follows the same shape on a different port. UDP is loss-tolerant by design, so HAProxy distributes rather than fails over. Cribl pipelines de-duplicate, parse flow records, and aggregate by tuple before forwarding.What lives where
DR posture
Splunk Cloud failover is provisioned viatofu-aws (private). It brings up cold AWS resources
(EC2, S3, Route 53) that accept the same HEC traffic if the home cluster is offline. Cribl Edge
routes can be flipped to point at the AWS endpoint with a single config change.