Alerting

Splunk add-on for cyberark syslog type

arrangineni
Path Finder

What kind of syslog server tool is best on Linux to capture the CyberArk logs into Splunk. We are planning to setup syslog on the heavy forwarder and directly monitor the inputs from the syslog location on the heavy forwarder.

 

Is it a best practice/doable to combine both on a same servers we don't have any dedicated syslog server in our environment? 

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...