<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: trying to replace Snare with Universal Forwarder.. syslog vs TCP in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/trying-to-replace-Snare-with-Universal-Forwarder-syslog-vs-TCP/m-p/72050#M8814</link>
    <description>&lt;P&gt;Snare Enterprise Agents provide TCP (with pooling), Smart Caching, record marking, Dynamic DNS names and multiple destinations. There are a lot of installation using Snare Agents to filter and forward in real time to Splunk for value.&lt;/P&gt;</description>
    <pubDate>Wed, 20 Mar 2013 15:56:58 GMT</pubDate>
    <dc:creator>peterbarzen</dc:creator>
    <dc:date>2013-03-20T15:56:58Z</dc:date>
    <item>
      <title>trying to replace Snare with Universal Forwarder.. syslog vs TCP</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/trying-to-replace-Snare-with-Universal-Forwarder-syslog-vs-TCP/m-p/72045#M8809</link>
      <description>&lt;P&gt;We currently use Snare to monitor windows eventlogs and various log files on many windows hosts. Snare currently, successfully forwards events to our splunk server via syslog using UDP/514. Having read a bit (quite a bit) about the new UF, I've been trying/testing using it in lieu of Snare. &lt;BR /&gt;
Initially I assumed it would be best to force the UF to send Syslog via UDP/514... because our Splunk server is already setup to receive it. So I edited the local\outputs.conf, replacing entire content with the 3 lines I believe are req'd to send events via Syslog. But I saw (and still see) no events leaving the UF box. &lt;/P&gt;

&lt;P&gt;My question is.... should I continue the effort to force UF to send syslog/UDP/514 or are the advantages of using the default TCP method so great I should simply head down that path?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2011 16:10:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/trying-to-replace-Snare-with-Universal-Forwarder-syslog-vs-TCP/m-p/72045#M8809</guid>
      <dc:creator>mikefoti</dc:creator>
      <dc:date>2011-09-08T16:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: trying to replace Snare with Universal Forwarder.. syslog vs TCP</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/trying-to-replace-Snare-with-Universal-Forwarder-syslog-vs-TCP/m-p/72046#M8810</link>
      <description>&lt;P&gt;I recommend going with the UF and using the regular splunk forwarder connections using TCP 9997, mainly because you are not guaranteed delivery with UDP - it's basically fire-and-forget. For a decent comparison between TCP and UDP check the following: &lt;A href="http://www.diffen.com/difference/TCP_vs_UDP" target="_blank"&gt;http://www.diffen.com/difference/TCP_vs_UDP&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;In addition to just using a more reliable protocol, the UF gives you a host of other useful features, such as queuing (indexer down -- no worries, data is queued and sent once indexer is available), bandwidth throttling, splunk app (config bundles) distribution, etc.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:52:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/trying-to-replace-Snare-with-Universal-Forwarder-syslog-vs-TCP/m-p/72046#M8810</guid>
      <dc:creator>ftk</dc:creator>
      <dc:date>2020-09-28T09:52:38Z</dc:date>
    </item>
    <item>
      <title>Re: trying to replace Snare with Universal Forwarder.. syslog vs TCP</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/trying-to-replace-Snare-with-Universal-Forwarder-syslog-vs-TCP/m-p/72047#M8811</link>
      <description>&lt;P&gt;Hey there, I am brand new to Splunk myself so I am just starting to get active here. But I'll toss in my two cents against my better judgement. Please everyone correct me if I am wrong. &lt;/P&gt;

&lt;P&gt;1) KISS, Keep it simple, if you can keep it out of box, please do. You might save yourself time with technical support someday later when upgrading. Or even more time training someone. &lt;/P&gt;

&lt;P&gt;2) TCP is reliable in transmission, as in error checking. So in theory, less likely to miss some data. &lt;A href="http://www.skullbox.net/tcpudp.php"&gt;http://www.skullbox.net/tcpudp.php&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I did a quick search for "Syslog on UDP vs TCP" and found a number of articles advocating TCP over UDP. Basically just because of the error checking. &lt;/P&gt;

&lt;P&gt;best of luck!&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2011 16:23:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/trying-to-replace-Snare-with-Universal-Forwarder-syslog-vs-TCP/m-p/72047#M8811</guid>
      <dc:creator>daniel333</dc:creator>
      <dc:date>2011-09-08T16:23:04Z</dc:date>
    </item>
    <item>
      <title>Re: trying to replace Snare with Universal Forwarder.. syslog vs TCP</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/trying-to-replace-Snare-with-Universal-Forwarder-syslog-vs-TCP/m-p/72048#M8812</link>
      <description>&lt;P&gt;There is an advantage of the UF monitoring windows event logs using WMI then forwarding over tcp on in the splunk format (splunktcp) to an indexer over snare to syslog, then index.&lt;BR /&gt;
this is that the window eventslogs sourcetypes have field extraction in splunk, while windows_snare_syslog don't.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:52:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/trying-to-replace-Snare-with-Universal-Forwarder-syslog-vs-TCP/m-p/72048#M8812</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2020-09-28T09:52:46Z</dc:date>
    </item>
    <item>
      <title>Re: trying to replace Snare with Universal Forwarder.. syslog vs TCP</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/trying-to-replace-Snare-with-Universal-Forwarder-syslog-vs-TCP/m-p/72049#M8813</link>
      <description>&lt;P&gt;Use UF, mainly because:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;tcp in better than udp (connectionless)&lt;/LI&gt;
&lt;LI&gt;connection between UF and Indexer is encrypted&lt;/LI&gt;
&lt;LI&gt;UF can be managed by deploymet-server&lt;/LI&gt;
&lt;LI&gt;UF can execute script, data routing, use WMI&lt;/LI&gt;
&lt;LI&gt;UF can be monitored by Splunk indexer (status, last connection, ecc..).&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;In 2 words: use UF &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2011 10:40:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/trying-to-replace-Snare-with-Universal-Forwarder-syslog-vs-TCP/m-p/72049#M8813</guid>
      <dc:creator>bizza</dc:creator>
      <dc:date>2011-09-09T10:40:27Z</dc:date>
    </item>
    <item>
      <title>Re: trying to replace Snare with Universal Forwarder.. syslog vs TCP</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/trying-to-replace-Snare-with-Universal-Forwarder-syslog-vs-TCP/m-p/72050#M8814</link>
      <description>&lt;P&gt;Snare Enterprise Agents provide TCP (with pooling), Smart Caching, record marking, Dynamic DNS names and multiple destinations. There are a lot of installation using Snare Agents to filter and forward in real time to Splunk for value.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2013 15:56:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/trying-to-replace-Snare-with-Universal-Forwarder-syslog-vs-TCP/m-p/72050#M8814</guid>
      <dc:creator>peterbarzen</dc:creator>
      <dc:date>2013-03-20T15:56:58Z</dc:date>
    </item>
    <item>
      <title>Re: trying to replace Snare with Universal Forwarder.. syslog vs TCP</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/trying-to-replace-Snare-with-Universal-Forwarder-syslog-vs-TCP/m-p/72051#M8815</link>
      <description>&lt;P&gt;You're not seeing data via Universal Forwarder because only the Heavyweight Forwarder can forward via syslog on UDP 514. TCP is a better bet though.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2013 20:20:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/trying-to-replace-Snare-with-Universal-Forwarder-syslog-vs-TCP/m-p/72051#M8815</guid>
      <dc:creator>Dimitri_McKay</dc:creator>
      <dc:date>2013-08-08T20:20:31Z</dc:date>
    </item>
  </channel>
</rss>

