All Apps and Add-ons

Do we need syslog-ng or rsyslog running if we are using the splunk unix/linux app?

ebethjones
New Member

We have syslog-ng configured to collect and forward logs from various network elements, but the linux servers that are running syslog-ng are not configured to collect any logs on themselves. If we deploy the splunk unix/linux app to collect data from these servers, is there any point in having syslog-ng collect logs locally for these servers? It looks like the app collects almost everything that would end up in /var/log/messages (i.e. collecting data from /var/log/audit and lsof). Is there any benefit in having syslog-ng writing the system info to /var/log/messages on these servers once we have the unix/linux app running?

0 Karma

southeringtonp
Motivator

Yes.

The Splunk forwarder typically gets data in two ways:

  1. By Running commands such as netstat to get information about system state (scripted inputs)
  2. By reading the contents of log files written by other applications, including those written by syslogd.

If you disable the local syslog daemon, then syslog data will not be be written to a file for Splunk to read. You would still be able to capture logs from applications that do not use syslog. For example, you'd still be able to get Apache access logs.

0 Karma
Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...