<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Logs directly to Splunk? in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Is-it-better-to-send-logs-directly-to-Splunk/m-p/652502#M13114</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/257228"&gt;@toddehb&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you are asking the innkeeper if the wine is good!&lt;/P&gt;&lt;P&gt;obviously We'll hint to use only Splunk as log management also because Splunk is the leader in SIEM and log management solutions and Greylog not.&lt;/P&gt;&lt;P&gt;In addition, having all logs in Splunk you can use them for your security and visibility searches in Splunk.&lt;/P&gt;&lt;P&gt;The only problem (I don't know the cost of Greylog) is that You pay Splunk license for the volume of indexed logs, so you pay more increasing the indexed logs, and to have a SIEM, you need to buy also a Premium app called Enterprise Security.&lt;/P&gt;&lt;P&gt;I worked with more SIEMs and I didn't find comaparble products, but as I said, I'm one of the innkeeper.&lt;/P&gt;&lt;P&gt;On this site you can find a comparison between Greylog to Splunk (&lt;A href="https://www.capterra.it/software/183539/graylog" target="_blank"&gt;https://www.capterra.it/software/183539/graylog&lt;/A&gt;) and this is a comparison between log management systems, Splunk in addition is also a SIEM (Using Enterprise Security), Greylog not!&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Mon, 31 Jul 2023 06:14:10 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-07-31T06:14:10Z</dc:date>
    <item>
      <title>Is it better to send logs directly to Splunk?</title>
      <link>https://community.splunk.com/t5/Installation/Is-it-better-to-send-logs-directly-to-Splunk/m-p/652474#M13113</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi, I am new to SIEM products. Does it make sense to sent all logs to Graylog first and from there to eg. Splunk or OSSIN? Or is it better to directly forward logs from the endpoints to SIEM?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2023 18:46:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Is-it-better-to-send-logs-directly-to-Splunk/m-p/652474#M13113</guid>
      <dc:creator>toddehb</dc:creator>
      <dc:date>2023-07-31T18:46:26Z</dc:date>
    </item>
    <item>
      <title>Re: Logs directly to Splunk?</title>
      <link>https://community.splunk.com/t5/Installation/Is-it-better-to-send-logs-directly-to-Splunk/m-p/652502#M13114</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/257228"&gt;@toddehb&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you are asking the innkeeper if the wine is good!&lt;/P&gt;&lt;P&gt;obviously We'll hint to use only Splunk as log management also because Splunk is the leader in SIEM and log management solutions and Greylog not.&lt;/P&gt;&lt;P&gt;In addition, having all logs in Splunk you can use them for your security and visibility searches in Splunk.&lt;/P&gt;&lt;P&gt;The only problem (I don't know the cost of Greylog) is that You pay Splunk license for the volume of indexed logs, so you pay more increasing the indexed logs, and to have a SIEM, you need to buy also a Premium app called Enterprise Security.&lt;/P&gt;&lt;P&gt;I worked with more SIEMs and I didn't find comaparble products, but as I said, I'm one of the innkeeper.&lt;/P&gt;&lt;P&gt;On this site you can find a comparison between Greylog to Splunk (&lt;A href="https://www.capterra.it/software/183539/graylog" target="_blank"&gt;https://www.capterra.it/software/183539/graylog&lt;/A&gt;) and this is a comparison between log management systems, Splunk in addition is also a SIEM (Using Enterprise Security), Greylog not!&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2023 06:14:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Is-it-better-to-send-logs-directly-to-Splunk/m-p/652502#M13114</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-07-31T06:14:10Z</dc:date>
    </item>
    <item>
      <title>Re: Logs directly to Splunk?</title>
      <link>https://community.splunk.com/t5/Installation/Is-it-better-to-send-logs-directly-to-Splunk/m-p/652504#M13115</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks. I read something, that graylog could normalize the logs and that would be better for splunk to work with. Don't know if it's true. For me it wouldn't make any difference. It is for my home lab and as I found out one can use Splunk with 500MB of logs for free. Think for at home that should be sufficient.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2023 06:32:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Is-it-better-to-send-logs-directly-to-Splunk/m-p/652504#M13115</guid>
      <dc:creator>toddehb</dc:creator>
      <dc:date>2023-07-31T06:32:51Z</dc:date>
    </item>
    <item>
      <title>Re: Logs directly to Splunk?</title>
      <link>https://community.splunk.com/t5/Installation/Is-it-better-to-send-logs-directly-to-Splunk/m-p/652505#M13116</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/257228"&gt;@toddehb&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;ok, good for you, remember that in this way, you cannot have the SIEM full features because you cannot use the Enterprise Security App, even if you can install two free apps:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Splunk Security Essentials (&lt;A href="https://splunkbase.splunk.com/app/3435" target="_blank"&gt;https://splunkbase.splunk.com/app/3435&lt;/A&gt;)&lt;/LI&gt;&lt;LI&gt;Splunk Alert Manager&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/2665" target="_blank"&gt;https://splunkbase.splunk.com/app/2665&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;and in this way create your own SIEM.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2023 06:40:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Is-it-better-to-send-logs-directly-to-Splunk/m-p/652505#M13116</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-07-31T06:40:28Z</dc:date>
    </item>
    <item>
      <title>Re: Is it better to send logs directly to Splunk?</title>
      <link>https://community.splunk.com/t5/Installation/Is-it-better-to-send-logs-directly-to-Splunk/m-p/652750#M13129</link>
      <description>&lt;P&gt;Two Cents - Depending on your operating environment, sending logs to a third party processor may be best as this will give you the ability to archive off your logs prior to the ingestion from Splunk in their rawest form (if required). Once data is indexed by Splunk the data cannot be considered pure as it could be modified via the Props/Transform command.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 18:48:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Is-it-better-to-send-logs-directly-to-Splunk/m-p/652750#M13129</guid>
      <dc:creator>Simple_Search</dc:creator>
      <dc:date>2023-08-01T18:48:44Z</dc:date>
    </item>
    <item>
      <title>Re: Is it better to send logs directly to Splunk?</title>
      <link>https://community.splunk.com/t5/Installation/Is-it-better-to-send-logs-directly-to-Splunk/m-p/652815#M13134</link>
      <description>&lt;P&gt;Thanks for your Input.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 05:58:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Is-it-better-to-send-logs-directly-to-Splunk/m-p/652815#M13134</guid>
      <dc:creator>toddehb</dc:creator>
      <dc:date>2023-08-02T05:58:53Z</dc:date>
    </item>
    <item>
      <title>Re: Is it better to send logs directly to Splunk?</title>
      <link>https://community.splunk.com/t5/Installation/Is-it-better-to-send-logs-directly-to-Splunk/m-p/652816#M13135</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/257228"&gt;@toddehb&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated by all the contributors &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 06:05:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Is-it-better-to-send-logs-directly-to-Splunk/m-p/652816#M13135</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-08-02T06:05:54Z</dc:date>
    </item>
  </channel>
</rss>

