<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Archsight to Splunk via UF /Syslog in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Archsight-to-Splunk-via-UF-Syslog/m-p/520998#M88046</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/132641"&gt;@sahiltcs&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;let me understand:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;you want to replace ArcSight with Splunk,&lt;/LI&gt;&lt;LI&gt;you want to take logs from Splunk UFs and syslogs from other systems,&lt;/LI&gt;&lt;LI&gt;ArcSight will send its logs in the migration and then it will be turned off;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;is this correct?&lt;/P&gt;&lt;P&gt;If this is your need, I think that you need to design an architecture of your infrastructure, this isn't a question for the Community, it requires and intervene of a Splunk Architect!&lt;/P&gt;&lt;P&gt;Anyway, few pills:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;if you need HA on data, you need to use an Indexers' Cluster,&lt;/LI&gt;&lt;LI&gt;if you need HA on front end, you need a Search Head Cluster,&lt;/LI&gt;&lt;LI&gt;the best approach is to put an UF in every server of your infrastructure,&lt;/LI&gt;&lt;LI&gt;UFs should be managed by a Deployment Server,&lt;/LI&gt;&lt;LI&gt;to take syslogs, it's a best practice to use two Heavy Forwarders with a Load Balancer in front.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Remember that Splunk license is countered only on the dayly indexed logs, this means that you can use all the Forwarders you need (Universal or Heavy) without additional costs.&lt;/P&gt;&lt;P&gt;The only eventual additional costs are Premium Apps (e.g. Enterprise Security , the Splunk SIEM) if you need them.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Wed, 23 Sep 2020 09:08:44 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2020-09-23T09:08:44Z</dc:date>
    <item>
      <title>Archsight to Splunk via UF /Syslog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Archsight-to-Splunk-via-UF-Syslog/m-p/520989#M88044</link>
      <description>&lt;P&gt;We are planning to migrate archsight to Splunk via Collection of UF , syslog&amp;nbsp; to HF.&lt;/P&gt;&lt;P&gt;How many UF we need to install , Do we need to require 1 UF for each data source.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2020 08:08:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Archsight-to-Splunk-via-UF-Syslog/m-p/520989#M88044</guid>
      <dc:creator>sahiltcs</dc:creator>
      <dc:date>2020-09-23T08:08:01Z</dc:date>
    </item>
    <item>
      <title>Re: Archsight to Splunk via UF /Syslog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Archsight-to-Splunk-via-UF-Syslog/m-p/520998#M88046</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/132641"&gt;@sahiltcs&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;let me understand:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;you want to replace ArcSight with Splunk,&lt;/LI&gt;&lt;LI&gt;you want to take logs from Splunk UFs and syslogs from other systems,&lt;/LI&gt;&lt;LI&gt;ArcSight will send its logs in the migration and then it will be turned off;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;is this correct?&lt;/P&gt;&lt;P&gt;If this is your need, I think that you need to design an architecture of your infrastructure, this isn't a question for the Community, it requires and intervene of a Splunk Architect!&lt;/P&gt;&lt;P&gt;Anyway, few pills:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;if you need HA on data, you need to use an Indexers' Cluster,&lt;/LI&gt;&lt;LI&gt;if you need HA on front end, you need a Search Head Cluster,&lt;/LI&gt;&lt;LI&gt;the best approach is to put an UF in every server of your infrastructure,&lt;/LI&gt;&lt;LI&gt;UFs should be managed by a Deployment Server,&lt;/LI&gt;&lt;LI&gt;to take syslogs, it's a best practice to use two Heavy Forwarders with a Load Balancer in front.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Remember that Splunk license is countered only on the dayly indexed logs, this means that you can use all the Forwarders you need (Universal or Heavy) without additional costs.&lt;/P&gt;&lt;P&gt;The only eventual additional costs are Premium Apps (e.g. Enterprise Security , the Splunk SIEM) if you need them.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2020 09:08:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Archsight-to-Splunk-via-UF-Syslog/m-p/520998#M88046</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-09-23T09:08:44Z</dc:date>
    </item>
    <item>
      <title>Re: Archsight to Splunk via UF /Syslog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Archsight-to-Splunk-via-UF-Syslog/m-p/521429#M88105</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/132641"&gt;@sahiltcs&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;good for you.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;PS.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 10:46:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Archsight-to-Splunk-via-UF-Syslog/m-p/521429#M88105</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-09-25T10:46:23Z</dc:date>
    </item>
    <item>
      <title>Re: Archsight to Splunk via UF /Syslog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Archsight-to-Splunk-via-UF-Syslog/m-p/521693#M88138</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;SPAN&gt;gcusello for the solution, Just one question&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;can you propose a Windows option to get from Syslog to HEC? Is there one?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 06:37:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Archsight-to-Splunk-via-UF-Syslog/m-p/521693#M88138</guid>
      <dc:creator>sahiltcs</dc:creator>
      <dc:date>2020-09-28T06:37:13Z</dc:date>
    </item>
    <item>
      <title>Re: Archsight to Splunk via UF /Syslog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Archsight-to-Splunk-via-UF-Syslog/m-p/521697#M88140</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/132641"&gt;@sahiltcs&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;as I said, if you haven't specific restrictions to agent use, I always hint for using Universal Forwarder that's few intrusive and consumes few system resources and, at the same time, gives you many usefule fuetures (log cache, packets compression, packets optimization, etc...).&lt;/P&gt;&lt;P&gt;About syslogs, are you speking of receive syslogs on a Windows machine or send syslogs from a Windows machine?&lt;/P&gt;&lt;P&gt;If you're speaking of receiving syslogs, you can use a syslog receinver or Splunk that has a syslog receiver embedded.&lt;/P&gt;&lt;P&gt;If you're speaking of sending syslogs from a windows machine, I'm not an expert, but I'm not sure that's possible, and anyway it's better to use a UF.&lt;/P&gt;&lt;P&gt;About HEC, I used this way only to receive logs from applications, and anyway UF is always the best solution.&lt;/P&gt;&lt;P&gt;At least, if you're speaking of using Windows as Operative System for the Splunk server, I always prefer Linux systems: I haven't any production Splunk architecture based on Windows server, with only one exception but it's very small and we're thinking to replace it.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;PS.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 06:54:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Archsight-to-Splunk-via-UF-Syslog/m-p/521697#M88140</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-09-28T06:54:29Z</dc:date>
    </item>
  </channel>
</rss>

