<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: syslog logs are missing in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/syslog-logs-are-missing/m-p/525201#M18101</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/226911"&gt;@msplunk33&lt;/a&gt;&amp;nbsp;do you use HF? do you use syslog-ng?&lt;BR /&gt;let the syslog servers send logs to a remote system and on that remote system, you can install UF/HF and collect the logs.. which is very efficient than UDP(as per my understanding).&lt;/P&gt;&lt;P&gt;&lt;A href="https://wiki.splunk.com/Community:Best_Practice_For_Configuring_Syslog_Input" target="_blank" rel="noopener"&gt;https://wiki.splunk.com/Community:Best_Practice_For_Configuring_Syslog_Input&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.splunk.com/en_us/blog/tips-and-tricks/splunk-connect-for-syslog-turnkey-and-scalable-syslog-gdi.html" target="_blank"&gt;https://www.splunk.com/en_us/blog/tips-and-tricks/splunk-connect-for-syslog-turnkey-and-scalable-syslog-gdi.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please check this Splunk Conf document:&lt;/P&gt;&lt;P&gt;&lt;A href="https://conf.splunk.com/files/2017/slides/the-critical-syslog-tricks-that-no-one-seems-to-know-about.pdf" target="_blank" rel="noopener"&gt;https://conf.splunk.com/files/2017/slides/the-critical-syslog-tricks-that-no-one-seems-to-know-about.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 17 Oct 2020 21:25:28 GMT</pubDate>
    <dc:creator>inventsekar</dc:creator>
    <dc:date>2020-10-17T21:25:28Z</dc:date>
    <item>
      <title>syslog logs are missing</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/syslog-logs-are-missing/m-p/525194#M18100</link>
      <description>&lt;P&gt;I am using linux rsyslog server to capture syslog from Cisco ASA firewall and send to the splunk using the universal forwarder. I have two syslog servers behind a load balancer for redundancy. The problem I am facing is I&amp;nbsp; am missing a lost of logs in syslog server. I know syslog use UDP traffic which is unreliable. Is there any way I can troubleshoot this issue. Is there any other better method l&amp;nbsp; can collect this syslog. I tried to send syslog to to splunk directly still I can see missing logs.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Oct 2020 20:35:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/syslog-logs-are-missing/m-p/525194#M18100</guid>
      <dc:creator>msplunk33</dc:creator>
      <dc:date>2020-10-17T20:35:13Z</dc:date>
    </item>
    <item>
      <title>Re: syslog logs are missing</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/syslog-logs-are-missing/m-p/525201#M18101</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/226911"&gt;@msplunk33&lt;/a&gt;&amp;nbsp;do you use HF? do you use syslog-ng?&lt;BR /&gt;let the syslog servers send logs to a remote system and on that remote system, you can install UF/HF and collect the logs.. which is very efficient than UDP(as per my understanding).&lt;/P&gt;&lt;P&gt;&lt;A href="https://wiki.splunk.com/Community:Best_Practice_For_Configuring_Syslog_Input" target="_blank" rel="noopener"&gt;https://wiki.splunk.com/Community:Best_Practice_For_Configuring_Syslog_Input&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.splunk.com/en_us/blog/tips-and-tricks/splunk-connect-for-syslog-turnkey-and-scalable-syslog-gdi.html" target="_blank"&gt;https://www.splunk.com/en_us/blog/tips-and-tricks/splunk-connect-for-syslog-turnkey-and-scalable-syslog-gdi.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please check this Splunk Conf document:&lt;/P&gt;&lt;P&gt;&lt;A href="https://conf.splunk.com/files/2017/slides/the-critical-syslog-tricks-that-no-one-seems-to-know-about.pdf" target="_blank" rel="noopener"&gt;https://conf.splunk.com/files/2017/slides/the-critical-syslog-tricks-that-no-one-seems-to-know-about.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 17 Oct 2020 21:25:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/syslog-logs-are-missing/m-p/525201#M18101</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2020-10-17T21:25:28Z</dc:date>
    </item>
    <item>
      <title>Re: syslog logs are missing</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/syslog-logs-are-missing/m-p/525212#M18103</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/80737"&gt;@inventsekar&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;yes this is a good approach. I have a question regarding the syslog. I am not very knowledgeable in syslog. Just want to clarify can we configure the network end device ( like CISCO ASA, Cisco switches etc) to send syslog into TCP port rather than UDp. As I know universally syslog use UDP port.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Oct 2020 01:40:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/syslog-logs-are-missing/m-p/525212#M18103</guid>
      <dc:creator>msplunk33</dc:creator>
      <dc:date>2020-10-18T01:40:28Z</dc:date>
    </item>
    <item>
      <title>Re: syslog logs are missing</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/syslog-logs-are-missing/m-p/525214#M18104</link>
      <description>&lt;P&gt;&lt;A href="https://qiita.com/odorusatoshi/items/5a703b9befc253ab7deb" target="_blank" rel="noopener"&gt;https://qiita.com/odorusatoshi/items/5a703b9befc253ab7deb&lt;/A&gt;&amp;nbsp; japanese&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;index=_internal host=your_syslog_host&lt;BR /&gt;check this result&lt;/P&gt;</description>
      <pubDate>Sun, 18 Oct 2020 01:54:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/syslog-logs-are-missing/m-p/525214#M18104</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-10-18T01:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: syslog logs are missing</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/syslog-logs-are-missing/m-p/525244#M18112</link>
      <description>In now a days this is doable in the most network equipments, unfortunately not in all. You must check it from you device’s manuals.&lt;BR /&gt;Still you should set up a separate syslog server to receive those events and then send/read those with/from it. Otherwise you will be lost event time by time (e.g. restarting HF/indexer).&lt;BR /&gt;r. Ismo</description>
      <pubDate>Sun, 18 Oct 2020 13:48:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/syslog-logs-are-missing/m-p/525244#M18112</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-10-18T13:48:28Z</dc:date>
    </item>
  </channel>
</rss>

