<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Syslog configuration in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Syslog-configuration/m-p/455802#M78833</link>
    <description>&lt;P&gt;Hi &lt;/P&gt;

&lt;P&gt;Need help on Syslog configuration setup. actually they are appliances with Linux OS. Any best practices would be very helpful.&lt;/P&gt;

&lt;P&gt;Is this setup needs to be on H.F? Or any other recommendations?&lt;/P&gt;

&lt;P&gt;Is there any Apps/Add-on's?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;</description>
    <pubDate>Mon, 25 Mar 2019 11:56:49 GMT</pubDate>
    <dc:creator>niha1318</dc:creator>
    <dc:date>2019-03-25T11:56:49Z</dc:date>
    <item>
      <title>Syslog configuration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Syslog-configuration/m-p/455802#M78833</link>
      <description>&lt;P&gt;Hi &lt;/P&gt;

&lt;P&gt;Need help on Syslog configuration setup. actually they are appliances with Linux OS. Any best practices would be very helpful.&lt;/P&gt;

&lt;P&gt;Is this setup needs to be on H.F? Or any other recommendations?&lt;/P&gt;

&lt;P&gt;Is there any Apps/Add-on's?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2019 11:56:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Syslog-configuration/m-p/455802#M78833</guid>
      <dc:creator>niha1318</dc:creator>
      <dc:date>2019-03-25T11:56:49Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog configuration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Syslog-configuration/m-p/455803#M78834</link>
      <description>&lt;P&gt;Hi niha1318. &lt;/P&gt;

&lt;P&gt;There are a few good resources on this but I definitely recommend taking a look at a couple of Splunk .Conf sessions on the topic. If you go to &lt;A href="https://conf.splunk.com/conf-online.html"&gt;https://conf.splunk.com/conf-online.html&lt;/A&gt; and search for FN1616 and FN123102 there are some good talks about getting syslog set up for Splunk. If you join the Splunk Community Slack channel (&lt;A href="https://splk.it/slack"&gt;https://splk.it/slack&lt;/A&gt;) there are several channels dedicated to syslog as well.&lt;/P&gt;

&lt;P&gt;You have the option of using a HF or UF but you want to avoid the HF if you can. The UF will be better for load balancing in a distributed environment and HF will increase resource usage and data sent across the network. If all you are doing is forwarding the data to your indexer(s) you can just use a UF. The apps/add-ons also depend on the data on syslog and whether or not you use a HF. If you use a heavy forwarder all of your parsing add-ons for the data on syslog would need to reside on the HF. Most add-ons will tell you whether or not they should be placed on a forwarder so it all depends on the kind of data you will be getting through syslog.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2019 14:17:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Syslog-configuration/m-p/455803#M78834</guid>
      <dc:creator>mdsnmss</dc:creator>
      <dc:date>2019-03-25T14:17:55Z</dc:date>
    </item>
  </channel>
</rss>

