Bro and Splunk forwarder

We’ve got a bro cluster up and running on our SciDMZ. I’m running the splunk forwarder on the head node. We’ve seen the splunk forwarder having issues after some time sending data. I’m not seeing anything in the system logs or splunk logs showing a reason.

Anyone running this type of configuration and seen contention?

Thanks,
Joseph

We used syslog to send the logs to a Splunk HF.