<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is sc4s log collector free as open-source rsyslog or it's counting as Splunk Enterprise license usage? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Is-sc4s-log-collector-free-as-open-source-rsyslog-or-it-s/m-p/636873#M26821</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;does getting all initial data from fw, network appliances, servers... in sc4s log collector is free as open-source rsyslog or it's counting as Splunk Enterprise license usage?&lt;/P&gt;
&lt;P&gt;Can we use it to also forward data to Elastic/Logstash (ELK) ?&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Wed, 14 Jun 2023 23:40:19 GMT</pubDate>
    <dc:creator>splunkreal</dc:creator>
    <dc:date>2023-06-14T23:40:19Z</dc:date>
    <item>
      <title>Is sc4s log collector free as open-source rsyslog or it's counting as Splunk Enterprise license usage?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Is-sc4s-log-collector-free-as-open-source-rsyslog-or-it-s/m-p/636873#M26821</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;does getting all initial data from fw, network appliances, servers... in sc4s log collector is free as open-source rsyslog or it's counting as Splunk Enterprise license usage?&lt;/P&gt;
&lt;P&gt;Can we use it to also forward data to Elastic/Logstash (ELK) ?&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2023 23:40:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Is-sc4s-log-collector-free-as-open-source-rsyslog-or-it-s/m-p/636873#M26821</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2023-06-14T23:40:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk sc4s log collector license</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Is-sc4s-log-collector-free-as-open-source-rsyslog-or-it-s/m-p/636876#M26822</link>
      <description>&lt;P&gt;SC4S is free to use just like a Splunk forwarder.&amp;nbsp; You cannot use it to forward to ELK since it uses HEC under the covers.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2023 13:10:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Is-sc4s-log-collector-free-as-open-source-rsyslog-or-it-s/m-p/636876#M26822</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-03-31T13:10:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk sc4s log collector license</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Is-sc4s-log-collector-free-as-open-source-rsyslog-or-it-s/m-p/638638#M27032</link>
      <description>&lt;P&gt;Hello Rich,&lt;/P&gt;&lt;P&gt;supports says "SC4S is free to use but if you store incoming data like rsyslog (log collector function) it will consume license."&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2023 12:14:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Is-sc4s-log-collector-free-as-open-source-rsyslog-or-it-s/m-p/638638#M27032</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2023-04-04T12:14:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk sc4s log collector license</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Is-sc4s-log-collector-free-as-open-source-rsyslog-or-it-s/m-p/638639#M27033</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/171872"&gt;@splunkreal&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;the meaning is: if you index logs from SC4S you consume license, if you use it to directly send data to another platform without indexing them on Splunk it's free.&lt;/P&gt;&lt;P&gt;Also because it's composed by a syslog-ng server and a Splunk Universal Forwarder.&lt;/P&gt;&lt;P&gt;But the question should be: why should you use it outside Splunk?&lt;/P&gt;&lt;P&gt;you could use the rsyslog server to write syslogs on disk and then the mechanism in the other platform (as Universal Forwarder in Splunk) to send data to it!&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2023 12:25:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Is-sc4s-log-collector-free-as-open-source-rsyslog-or-it-s/m-p/638639#M27033</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-04-04T12:25:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk sc4s log collector license</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Is-sc4s-log-collector-free-as-open-source-rsyslog-or-it-s/m-p/638641#M27034</link>
      <description>&lt;P&gt;They pretty much confirmed what I said.&amp;nbsp; SC4S itself has no cost.&amp;nbsp; The storage of data is the same regardless of how it gets to Splunk.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2023 12:30:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Is-sc4s-log-collector-free-as-open-source-rsyslog-or-it-s/m-p/638641#M27034</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-04-04T12:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk sc4s log collector license</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Is-sc4s-log-collector-free-as-open-source-rsyslog-or-it-s/m-p/638643#M27035</link>
      <description>&lt;P&gt;So I understand sc4s does not store incoming data on disk but directly forwards data to indexers so it consumes license?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2023 12:32:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Is-sc4s-log-collector-free-as-open-source-rsyslog-or-it-s/m-p/638643#M27035</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2023-04-04T12:32:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk sc4s log collector license</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Is-sc4s-log-collector-free-as-open-source-rsyslog-or-it-s/m-p/638644#M27036</link>
      <description>&lt;P&gt;We also need to store data on disk and not directly forward...&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2023 12:33:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Is-sc4s-log-collector-free-as-open-source-rsyslog-or-it-s/m-p/638644#M27036</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2023-04-04T12:33:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk sc4s log collector license</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Is-sc4s-log-collector-free-as-open-source-rsyslog-or-it-s/m-p/638656#M27037</link>
      <description>&lt;P&gt;SC4S may cache data temporarily if it can't reach any indexers.&amp;nbsp; Splunk does not charge for that.&lt;/P&gt;&lt;P&gt;Any data sent by SC4S to your indexers that is written to an index will consume ingestion license.&lt;/P&gt;&lt;P&gt;In both respects, SC4S is no different from a Universal Forwarder.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2023 13:21:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Is-sc4s-log-collector-free-as-open-source-rsyslog-or-it-s/m-p/638656#M27037</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-04-04T13:21:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk sc4s log collector license</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Is-sc4s-log-collector-free-as-open-source-rsyslog-or-it-s/m-p/638661#M27039</link>
      <description>&lt;P&gt;So sc4s is just a filter, we can't use it as log collector to store data for several months if I understood?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2023 13:39:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Is-sc4s-log-collector-free-as-open-source-rsyslog-or-it-s/m-p/638661#M27039</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2023-04-04T13:39:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk sc4s log collector license</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Is-sc4s-log-collector-free-as-open-source-rsyslog-or-it-s/m-p/638665#M27040</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;BTW would you recommend using UF to forward&amp;nbsp; high volume of data from rsyslog to Splunk indexers?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2023 14:14:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Is-sc4s-log-collector-free-as-open-source-rsyslog-or-it-s/m-p/638665#M27040</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2023-04-04T14:14:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk sc4s log collector license</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Is-sc4s-log-collector-free-as-open-source-rsyslog-or-it-s/m-p/638666#M27041</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/171872"&gt;@splunkreal&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I usually use this approach in my projects: rsyslog and UF.&lt;/P&gt;&lt;P&gt;Also because some of my colleagues, more expert than me about Linux hinted to prefer rsyslog than syslog-ng.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2023 14:20:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Is-sc4s-log-collector-free-as-open-source-rsyslog-or-it-s/m-p/638666#M27041</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-04-04T14:20:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk sc4s log collector license</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Is-sc4s-log-collector-free-as-open-source-rsyslog-or-it-s/m-p/638668#M27042</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/171872"&gt;@splunkreal&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;So sc4s is just a filter, we can't use it as log collector to store data for several months if I understood?&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;BR /&gt;That is correct. SC4S is a transient combined syslog receiver and Splunk forwarder. It is not a useful tool without a platform (Splunk) to send the data to.&lt;BR /&gt;The big advantage with SC4S is the "rule soup" which helps classify and route data into appropriate sourcetypes and indexes without needing any further configuration&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2023 14:34:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Is-sc4s-log-collector-free-as-open-source-rsyslog-or-it-s/m-p/638668#M27042</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2023-04-04T14:34:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk sc4s log collector license</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Is-sc4s-log-collector-free-as-open-source-rsyslog-or-it-s/m-p/646871#M27205</link>
      <description>&lt;P&gt;I would add that it's likely license usage would be greater for syslog ingested as HEC (being json) vs ingested as old school text log files.&lt;BR /&gt;&lt;BR /&gt;In that sense, SC4S would likely cause greater license usage than syslog, though you would save local disk capacity from having to store files until ingested. Just compare a text log file to it's json equivalent.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2023 21:02:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Is-sc4s-log-collector-free-as-open-source-rsyslog-or-it-s/m-p/646871#M27205</guid>
      <dc:creator>moliminous</dc:creator>
      <dc:date>2023-06-13T21:02:47Z</dc:date>
    </item>
  </channel>
</rss>

