<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Separating logs from different environments in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Separating-logs-from-different-environments/m-p/577581#M8625</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/7790"&gt;@nembela&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;at first the choose of an index depends on two reasons.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;retention,&lt;/LI&gt;&lt;LI&gt;accesses.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;usually non prod logs have a different retention and different access grants.&lt;/P&gt;&lt;P&gt;if both logs have the same retention and the same accesses, you can out them in the same index, otherwise you have to put them in different indexes.&lt;/P&gt;&lt;P&gt;In addition, it could depend on the reasons related to these logs:&lt;/P&gt;&lt;P&gt;do you want to make the same monitoring of the production logs?&lt;/P&gt;&lt;P&gt;e.g.: if you want to monitor only prod systems it's easier to have non prod logs in a different index.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Tue, 07 Dec 2021 09:55:41 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2021-12-07T09:55:41Z</dc:date>
    <item>
      <title>Separating logs from different environments</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Separating-logs-from-different-environments/m-p/577580#M8624</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Till now we only collected logs from production servers with Splunk. But soon we will onboard the system logs from non-prod (Linux, Windows) servers.&lt;/P&gt;&lt;P&gt;What is the best way to differentiate between the logs from different environents?&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;different index? All these logs have the same retention time&lt;/LI&gt;&lt;LI&gt;different sourcetype? All the logs are system logs (Windows, Linux)&lt;/LI&gt;&lt;LI&gt;eventtype?&lt;/LI&gt;&lt;LI&gt;a dedicated "environment" field?&lt;/LI&gt;&lt;LI&gt;tagging?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Laci&lt;/P&gt;</description>
      <pubDate>Tue, 07 Dec 2021 09:47:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Separating-logs-from-different-environments/m-p/577580#M8624</guid>
      <dc:creator>nembela</dc:creator>
      <dc:date>2021-12-07T09:47:56Z</dc:date>
    </item>
    <item>
      <title>Re: Separating logs from different environments</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Separating-logs-from-different-environments/m-p/577581#M8625</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/7790"&gt;@nembela&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;at first the choose of an index depends on two reasons.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;retention,&lt;/LI&gt;&lt;LI&gt;accesses.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;usually non prod logs have a different retention and different access grants.&lt;/P&gt;&lt;P&gt;if both logs have the same retention and the same accesses, you can out them in the same index, otherwise you have to put them in different indexes.&lt;/P&gt;&lt;P&gt;In addition, it could depend on the reasons related to these logs:&lt;/P&gt;&lt;P&gt;do you want to make the same monitoring of the production logs?&lt;/P&gt;&lt;P&gt;e.g.: if you want to monitor only prod systems it's easier to have non prod logs in a different index.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 07 Dec 2021 09:55:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Separating-logs-from-different-environments/m-p/577581#M8625</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-12-07T09:55:41Z</dc:date>
    </item>
    <item>
      <title>Re: Separating logs from different environments</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Separating-logs-from-different-environments/m-p/577582#M8626</link>
      <description>&lt;P&gt;It depends on what you want to do with the information.&lt;/P&gt;&lt;P&gt;Do you want to be able to distinguish which environment an event came from?&lt;/P&gt;&lt;P&gt;Do you want to be able to mix events from different environments into the same search/dashboard?&lt;/P&gt;&lt;P&gt;Can you use the host field to determine which environment the event came from, e.g. by a simple lookup?&lt;/P&gt;&lt;P&gt;Are the log formats the same across all environments?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Dec 2021 09:57:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Separating-logs-from-different-environments/m-p/577582#M8626</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-12-07T09:57:22Z</dc:date>
    </item>
    <item>
      <title>Re: Separating logs from different environments</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Separating-logs-from-different-environments/m-p/577584#M8627</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;In the first step is looking if there are any regulation or legislations which force you to use separate environments or can you still use the same for production and test. Also you must check what kind of access restrictions there are in your enterprise for logs. Who can see production and who can access test logs. Usually those are at least partially different groups and quite often it's not allowed for any individual person to see both.&lt;/P&gt;&lt;P&gt;After you have gotten answers to above questions then you can continue with&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;'s and&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;'s guidelines.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Tue, 07 Dec 2021 10:12:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Separating-logs-from-different-environments/m-p/577584#M8627</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-12-07T10:12:38Z</dc:date>
    </item>
    <item>
      <title>Re: Separating logs from different environments</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Separating-logs-from-different-environments/m-p/577599#M8628</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the ideas. I'll try to answer the questions in one post.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;: We have regulations that requrire the collection of logs from environments where the data is not fully anonimized (e.g. staging and test). But we can use the same Splunk instance for all these logs.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;: Because these are standard OS logs, the same teams need to access/monitor them. We don't need to give access to developers because there are no application logs.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Do you want to be able to distinguish which environment an event came from? &lt;STRONG&gt;Yes&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;Do you want to be able to mix events from different environments into the same search/dashboard? &lt;STRONG&gt;Yes&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;Can you use the host field to determine which environment the event came from, e.g. by a simple lookup? &lt;STRONG&gt;Yes, but it will need definitely some manual work&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;Are the log formats the same across all environments? &lt;STRONG&gt;Yes, normal Linux and Windows OS logs&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Tue, 07 Dec 2021 11:21:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Separating-logs-from-different-environments/m-p/577599#M8628</guid>
      <dc:creator>nembela</dc:creator>
      <dc:date>2021-12-07T11:21:26Z</dc:date>
    </item>
    <item>
      <title>Re: Separating logs from different environments</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Separating-logs-from-different-environments/m-p/577603#M8629</link>
      <description>&lt;P&gt;Possibly the simplest way is to perform a lookup at ingestion time based on the host and set an "environment" field to "tag" the event with the environment it belongs to. When the hosts for an environment change, you should just need to update the lookup store. Initial set up might need some manual work, but it provides a reasonably flexible solution should the purpose of a host moves from one environment to another as the purpose at the time of ingestion would be preserved.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Dec 2021 11:35:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Separating-logs-from-different-environments/m-p/577603#M8629</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-12-07T11:35:58Z</dc:date>
    </item>
    <item>
      <title>Re: Separating logs from different environments</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Separating-logs-from-different-environments/m-p/577608#M8630</link>
      <description>&lt;P&gt;You can also just modify the source field. I know that typically source represents the forwarder's point of view, but sometimes it's convenient to change it. For example, when I use syslog-&amp;gt;rsyslog-&amp;gt;HEC infrastructure I modify the source field to include the IP of the source host. I know that sc4s adds additional field for that but we wanted to do without adding extra metadata to events.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Dec 2021 12:18:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Separating-logs-from-different-environments/m-p/577608#M8630</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-12-07T12:18:51Z</dc:date>
    </item>
  </channel>
</rss>

