<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Syslog vs TA apps to parse network traffic sourcetypes in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Syslog-vs-TA-apps-to-parse-network-traffic-sourcetypes/m-p/517137#M87514</link>
    <description>&lt;P&gt;Best Practice is to NOT log UDP/TCP directly to Splunk.&amp;nbsp; Doing so can lead to data loss.&amp;nbsp; Syslog events should go to a syslog server.&lt;/P&gt;</description>
    <pubDate>Tue, 01 Sep 2020 00:31:30 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2020-09-01T00:31:30Z</dc:date>
    <item>
      <title>Syslog vs TA apps to parse network traffic sourcetypes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Syslog-vs-TA-apps-to-parse-network-traffic-sourcetypes/m-p/517133#M87513</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We are trying to ingest some logs for events from different network appliances such as F5 load balancers.&amp;nbsp; Can you please tell us whether we should be logging them to a syslog and ingesting them from there or if we should be collecting them with splunk listening on a UDP port?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2020 22:45:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Syslog-vs-TA-apps-to-parse-network-traffic-sourcetypes/m-p/517133#M87513</guid>
      <dc:creator>sdintino_splunk</dc:creator>
      <dc:date>2020-08-31T22:45:38Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog vs TA apps to parse network traffic sourcetypes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Syslog-vs-TA-apps-to-parse-network-traffic-sourcetypes/m-p/517137#M87514</link>
      <description>&lt;P&gt;Best Practice is to NOT log UDP/TCP directly to Splunk.&amp;nbsp; Doing so can lead to data loss.&amp;nbsp; Syslog events should go to a syslog server.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2020 00:31:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Syslog-vs-TA-apps-to-parse-network-traffic-sourcetypes/m-p/517137#M87514</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-09-01T00:31:30Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog vs TA apps to parse network traffic sourcetypes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Syslog-vs-TA-apps-to-parse-network-traffic-sourcetypes/m-p/517147#M87517</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;just like&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;said. If you are logging UDP directly to splunk it’s not if you lost events, it’s how often and how much you will be lost them.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2020 04:35:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Syslog-vs-TA-apps-to-parse-network-traffic-sourcetypes/m-p/517147#M87517</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-09-01T04:35:38Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog vs TA apps to parse network traffic sourcetypes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Syslog-vs-TA-apps-to-parse-network-traffic-sourcetypes/m-p/517239#M87533</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt; ! This confirms what I'd thought. Much appreciated!&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2020 14:00:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Syslog-vs-TA-apps-to-parse-network-traffic-sourcetypes/m-p/517239#M87533</guid>
      <dc:creator>sdintino_splunk</dc:creator>
      <dc:date>2020-09-01T14:00:16Z</dc:date>
    </item>
  </channel>
</rss>

