<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Linux servers - Universal Forwarder or Syslog in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Linux-servers-Universal-Forwarder-or-Syslog/m-p/451333#M5920</link>
    <description>&lt;P&gt;Thank you; this was very helpful!&lt;/P&gt;</description>
    <pubDate>Thu, 19 Jul 2018 00:11:28 GMT</pubDate>
    <dc:creator>dyeo</dc:creator>
    <dc:date>2018-07-19T00:11:28Z</dc:date>
    <item>
      <title>Linux servers - Universal Forwarder or Syslog</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Linux-servers-Universal-Forwarder-or-Syslog/m-p/451331#M5918</link>
      <description>&lt;P&gt;What is the best practice to capture data from our *nix servers?  Install the Splunk forwarder agent and the Splunk for Unix app which feeds directly to our indexers?  I thought a best practice was to have everything syslog-ed before being indexed.  &lt;/P&gt;

&lt;P&gt;If we only use remote syslog on our servers (not having the Splunk forwarder agent on our servers), I'm assuming we won't get the metrics that the Splunk for Unix app polls for.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jul 2018 21:45:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Linux-servers-Universal-Forwarder-or-Syslog/m-p/451331#M5918</guid>
      <dc:creator>dyeo</dc:creator>
      <dc:date>2018-07-18T21:45:49Z</dc:date>
    </item>
    <item>
      <title>Re: Linux servers - Universal Forwarder or Syslog</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Linux-servers-Universal-Forwarder-or-Syslog/m-p/451332#M5919</link>
      <description>&lt;P&gt;Hi Dyeo,&lt;/P&gt;

&lt;P&gt;This blog is pretty old but will help you decide on which practice is better.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://www.splunk.com/blog/2011/10/24/choosing-a-forwarder-or-not.html"&gt;https://www.splunk.com/blog/2011/10/24/choosing-a-forwarder-or-not.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 00:04:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Linux-servers-Universal-Forwarder-or-Syslog/m-p/451332#M5919</guid>
      <dc:creator>pruthvikrishnap</dc:creator>
      <dc:date>2018-07-19T00:04:02Z</dc:date>
    </item>
    <item>
      <title>Re: Linux servers - Universal Forwarder or Syslog</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Linux-servers-Universal-Forwarder-or-Syslog/m-p/451333#M5920</link>
      <description>&lt;P&gt;Thank you; this was very helpful!&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 00:11:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Linux-servers-Universal-Forwarder-or-Syslog/m-p/451333#M5920</guid>
      <dc:creator>dyeo</dc:creator>
      <dc:date>2018-07-19T00:11:28Z</dc:date>
    </item>
    <item>
      <title>Re: Linux servers - Universal Forwarder or Syslog</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Linux-servers-Universal-Forwarder-or-Syslog/m-p/451334#M5921</link>
      <description>&lt;P&gt;Typically, we would suggest a Universal Forwarder on the *nix server.  This removes any latency that might be introduced by forwarding the syslogs to a syslog server, and also allows you to collect performance data and other logs from the server.  The recommendation to use a syslog server is generally for devices or appliances that don't allow for the installation of a forwarder.  My rule of thumb is to collect the data at the source whenever possible. &lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 02:59:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Linux-servers-Universal-Forwarder-or-Syslog/m-p/451334#M5921</guid>
      <dc:creator>kmorris_splunk</dc:creator>
      <dc:date>2018-07-19T02:59:50Z</dc:date>
    </item>
    <item>
      <title>Re: Linux servers - Universal Forwarder or Syslog</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Linux-servers-Universal-Forwarder-or-Syslog/m-p/451335#M5922</link>
      <description>&lt;P&gt;Also prevents difficulties with missing timezone information. Hundreds of servers with arbitrary time zone config logging to a central syslog server can be a serious nightmare to deal with if the servers are not including timezone in their syslog message (which in default basic syslog forwarding format is not included).&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 06:55:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Linux-servers-Universal-Forwarder-or-Syslog/m-p/451335#M5922</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-07-19T06:55:38Z</dc:date>
    </item>
  </channel>
</rss>

