I am new to haproxy usage, i wanted to check one thing here.
In the below architecture, When output servers (in my case it is SIEM) are down and not able to receive any logs which are sent by logstash through haproxy.
We can’t stop the input flow from logstash to haproxy but the SIEM is not available to accept/receive logs from haproxy.
So does haproxy can keep the buffer of failed logs and resend it again ? or do we face log loss in this situation?
Would be much helpful if someone can help me in this. Thanks.