<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Recommended R-Syslog equivalent collector for Windows systems. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Recommended-R-Syslog-equivalent-collector-for-Windows-systems/m-p/475897#M81671</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;If all those hosts are windows then maybe the easiest way is put one or more heavy/universal  forwarders there as “gateway forwarder”. Then point all other UFs to send to those and those relay events to your main site.&lt;/P&gt;

&lt;P&gt;R. Ismo&lt;/P&gt;</description>
    <pubDate>Wed, 19 Feb 2020 17:46:16 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2020-02-19T17:46:16Z</dc:date>
    <item>
      <title>Recommended R-Syslog equivalent collector for Windows systems.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Recommended-R-Syslog-equivalent-collector-for-Windows-systems/m-p/475896#M81670</link>
      <description>&lt;P&gt;Hello, &lt;/P&gt;

&lt;P&gt;We have a relatively small network on a remote location that needs to forward logs onto our Splunk Instance, this remote system has particularly low bandwidth per its location.&lt;/P&gt;

&lt;P&gt;During our Splunk original architecture call we were advised to setup a syslog collector on this remote network, and setup a scheduled time were logs can be forwarded to the Main Splunk instance for indexing with the idea being setting this task for overnight hours.&lt;/P&gt;

&lt;P&gt;Since ALL systems are Windows based in this remote location, the current question we face is, in your experience - Which is the preferred syslog collector for Windows that will easily integrate with Splunk?&lt;BR /&gt;
is Syslog-NG the best/most common application for this task?&lt;/P&gt;

&lt;P&gt;thank you,&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2020 15:54:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Recommended-R-Syslog-equivalent-collector-for-Windows-systems/m-p/475896#M81670</guid>
      <dc:creator>offspringinc</dc:creator>
      <dc:date>2020-02-18T15:54:17Z</dc:date>
    </item>
    <item>
      <title>Re: Recommended R-Syslog equivalent collector for Windows systems.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Recommended-R-Syslog-equivalent-collector-for-Windows-systems/m-p/475897#M81671</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;If all those hosts are windows then maybe the easiest way is put one or more heavy/universal  forwarders there as “gateway forwarder”. Then point all other UFs to send to those and those relay events to your main site.&lt;/P&gt;

&lt;P&gt;R. Ismo&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 17:46:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Recommended-R-Syslog-equivalent-collector-for-Windows-systems/m-p/475897#M81671</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-02-19T17:46:16Z</dc:date>
    </item>
    <item>
      <title>Re: Recommended R-Syslog equivalent collector for Windows systems.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Recommended-R-Syslog-equivalent-collector-for-Windows-systems/m-p/475898#M81672</link>
      <description>&lt;P&gt;Perhaps you should consider using Windows Event Forwarding to a local server (&lt;A href="https://docs.microsoft.com/en-us/advanced-threat-analytics/configure-event-collection"&gt;https://docs.microsoft.com/en-us/advanced-threat-analytics/configure-event-collection&lt;/A&gt;) and use a Splunk forwarder to send the logs to your Splunk instance. To meet your need to send the logs off-hours, write a powershell script to enable/disable splunkd as required to meet your transmission requirements.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 18:01:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Recommended-R-Syslog-equivalent-collector-for-Windows-systems/m-p/475898#M81672</guid>
      <dc:creator>mydog8it</dc:creator>
      <dc:date>2020-02-19T18:01:18Z</dc:date>
    </item>
    <item>
      <title>Re: Recommended R-Syslog equivalent collector for Windows systems.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Recommended-R-Syslog-equivalent-collector-for-Windows-systems/m-p/475899#M81673</link>
      <description>&lt;P&gt;Yes, that may be a good option and because our limited bandwidth is our biggest challenge, to the tune of  1mb up/down rural and unsteady speeds we really need to limit log forwarding to a specific time of night.&lt;/P&gt;

&lt;P&gt;Another point I forgot to note is that we'll be 'eventually' adding networking devices such as Firewall, Network Switches, and a VPN appliance, these will need a syslog server. &lt;BR /&gt;
We use R-Syslog on our parent network, and for that reason we're looking at alternatives that have worked well for you guys to use with Splunk from a Windows System, unfortunately standing up a Linux server is not an option in this environment.&lt;/P&gt;

&lt;P&gt;Any other syslog servers recommendations welcomed.&lt;/P&gt;

&lt;P&gt;Thank you folks.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 18:16:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Recommended-R-Syslog-equivalent-collector-for-Windows-systems/m-p/475899#M81673</guid>
      <dc:creator>offspringinc</dc:creator>
      <dc:date>2020-02-19T18:16:17Z</dc:date>
    </item>
  </channel>
</rss>

