All Apps and Add-ons

Do we need syslog-ng or rsyslog running if we are using the splunk unix/linux app?

ebethjones
New Member

We have syslog-ng configured to collect and forward logs from various network elements, but the linux servers that are running syslog-ng are not configured to collect any logs on themselves. If we deploy the splunk unix/linux app to collect data from these servers, is there any point in having syslog-ng collect logs locally for these servers? It looks like the app collects almost everything that would end up in /var/log/messages (i.e. collecting data from /var/log/audit and lsof). Is there any benefit in having syslog-ng writing the system info to /var/log/messages on these servers once we have the unix/linux app running?

0 Karma

southeringtonp
Motivator

Yes.

The Splunk forwarder typically gets data in two ways:

  1. By Running commands such as netstat to get information about system state (scripted inputs)
  2. By reading the contents of log files written by other applications, including those written by syslogd.

If you disable the local syslog daemon, then syslog data will not be be written to a file for Splunk to read. You would still be able to capture logs from applications that do not use syslog. For example, you'd still be able to get Apache access logs.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...