<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ingesting syslog data in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/ingesting-syslog-data/m-p/753201#M29684</link>
    <description>&lt;P&gt;&lt;A href="https://help.splunk.com/en/splunk-cloud-platform/splunk-validated-architectures/getting-data-in-forwarding-and-preprocessing/syslog-data-collection" target="_blank"&gt;https://help.splunk.com/en/splunk-cloud-platform/splunk-validated-architectures/getting-data-in-forwarding-and-preprocessing/syslog-data-collection&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 17 Sep 2025 05:24:19 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2025-09-17T05:24:19Z</dc:date>
    <item>
      <title>ingesting syslog data</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/ingesting-syslog-data/m-p/753142#M29680</link>
      <description>&lt;P&gt;I want to ingest syslog from different devices like ESXI Hosts, firewalls (fortigate, palo alto), switches can somebody answer how can I achieve this?&amp;nbsp; I was thinking if I can forward syslog to HF and then to indexers but not aware of the full process. Please let me know if there are any other methods as well.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Sep 2025 13:59:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/ingesting-syslog-data/m-p/753142#M29680</guid>
      <dc:creator>maheshnc</dc:creator>
      <dc:date>2025-09-16T13:59:17Z</dc:date>
    </item>
    <item>
      <title>Re: ingesting syslog data</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/ingesting-syslog-data/m-p/753148#M29681</link>
      <description>&lt;P&gt;There are a few ways to onboard data into Splunk.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Install a universal forwarder on the server to send log files to Splunk&lt;/LI&gt;&lt;LI&gt;Have the server send syslog data to Splunk via a syslog server or Splunk Connect for Syslog&lt;/LI&gt;&lt;LI&gt;Use the server's API to extract data for indexing&lt;/LI&gt;&lt;LI&gt;Use Splunk DB Connect to pull data from the server's SQL database.&lt;/LI&gt;&lt;LI&gt;Have the application send data directly to Splunk using HTTP Event Collector (HEC).&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Tue, 16 Sep 2025 14:25:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/ingesting-syslog-data/m-p/753148#M29681</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2025-09-16T14:25:22Z</dc:date>
    </item>
    <item>
      <title>Re: ingesting syslog data</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/ingesting-syslog-data/m-p/753169#M29682</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/312895"&gt;@maheshnc&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I usually use rsyslog on a Universal or Heavy Forwarder to receive syslogs also when Splunk is down on this machine.&lt;/P&gt;&lt;P&gt;The best solution is to have two (or more) machines with rsyslog receiver and a Load Balancer in front of them, so you have also HA features in your architecture and you can receive logs even if one of the receivers is down.&lt;/P&gt;&lt;P&gt;Then files written by rsyslog can be read by Splunk Forwarder and sent to Indexers.&lt;/P&gt;&lt;P&gt;In the rsyslog, you can also configure host and technology recognition.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 16 Sep 2025 16:46:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/ingesting-syslog-data/m-p/753169#M29682</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-09-16T16:46:27Z</dc:date>
    </item>
    <item>
      <title>Re: ingesting syslog data</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/ingesting-syslog-data/m-p/753200#M29683</link>
      <description>&lt;P&gt;Is it possible to configure the syslog device to send data to HF and then forward it to the indexers?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Sep 2025 05:20:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/ingesting-syslog-data/m-p/753200#M29683</guid>
      <dc:creator>maheshnc</dc:creator>
      <dc:date>2025-09-17T05:20:58Z</dc:date>
    </item>
    <item>
      <title>Re: ingesting syslog data</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/ingesting-syslog-data/m-p/753201#M29684</link>
      <description>&lt;P&gt;&lt;A href="https://help.splunk.com/en/splunk-cloud-platform/splunk-validated-architectures/getting-data-in-forwarding-and-preprocessing/syslog-data-collection" target="_blank"&gt;https://help.splunk.com/en/splunk-cloud-platform/splunk-validated-architectures/getting-data-in-forwarding-and-preprocessing/syslog-data-collection&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Sep 2025 05:24:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/ingesting-syslog-data/m-p/753201#M29684</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-09-17T05:24:19Z</dc:date>
    </item>
    <item>
      <title>Re: ingesting syslog data</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/ingesting-syslog-data/m-p/753364#M29696</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/312895"&gt;@maheshnc&lt;/a&gt;&amp;nbsp; Yes that is possible , you can&amp;nbsp;&lt;SPAN&gt;configure the syslog device to send data to HF and then forward it to the indexers.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Sep 2025 02:12:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/ingesting-syslog-data/m-p/753364#M29696</guid>
      <dc:creator>kml_uvce</dc:creator>
      <dc:date>2025-09-22T02:12:27Z</dc:date>
    </item>
    <item>
      <title>Re: ingesting syslog data</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/ingesting-syslog-data/m-p/753373#M29697</link>
      <description>&lt;P&gt;Could you please through some light on process and configurations to be done, as I have not onboarded it before.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Sep 2025 05:20:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/ingesting-syslog-data/m-p/753373#M29697</guid>
      <dc:creator>maheshnc</dc:creator>
      <dc:date>2025-09-22T05:20:39Z</dc:date>
    </item>
    <item>
      <title>Re: ingesting syslog data</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/ingesting-syslog-data/m-p/753420#M29698</link>
      <description>&lt;P&gt;You can enable a tcp or udp source on a Splunk component. But. The other ways of handling syslogs are usually better - more robust, easier to maintain, less downtime needed for maintenance and so on.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Sep 2025 12:01:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/ingesting-syslog-data/m-p/753420#M29698</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-09-22T12:01:46Z</dc:date>
    </item>
    <item>
      <title>Re: ingesting syslog data</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/ingesting-syslog-data/m-p/753486#M29700</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/312895"&gt;@maheshnc&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;the process is linear:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;choose a protocol (UDP or TCP) and a port to use (default 514),&lt;/LI&gt;&lt;LI&gt;check the firewall routes between the source devices and the receiver for the defined protocol and port,&lt;/LI&gt;&lt;LI&gt;configure rsyslog to receive syslogs and write logs in a folder using the defined protocol and port,&lt;/LI&gt;&lt;LI&gt;configure the Splunk Forwarder (Universal or Heavy) to send logs to the Indexers (outputs.conf),&lt;/LI&gt;&lt;LI&gt;configure the Splunk Forwarder (Universal or Heavy) to read the files containing syslogs (inputs.conf),&lt;/LI&gt;&lt;LI&gt;define and install the add-ons to use to parse your data.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;to have more information about rsyslog configuration, you can read at&amp;nbsp;&lt;A href="https://www.rsyslog.com/doc/index.html" target="_blank"&gt;https://www.rsyslog.com/doc/index.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 23 Sep 2025 07:59:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/ingesting-syslog-data/m-p/753486#M29700</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-09-23T07:59:35Z</dc:date>
    </item>
    <item>
      <title>Re: ingesting syslog data</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/ingesting-syslog-data/m-p/753494#M29701</link>
      <description>&lt;P&gt;With a fairly modern rsyslog you can send directly to HEC input bypassing the need to create local files.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Sep 2025 13:48:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/ingesting-syslog-data/m-p/753494#M29701</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-09-23T13:48:47Z</dc:date>
    </item>
  </channel>
</rss>

