Hi All,
How to onboard Tandem XMA data to splunk?
Hi @blbr123,
I didn't used Tandem XMA before, but in general, you have to understand how Tandem XMA can send its logs (e.g. syslog or Forwarders) and then configure Splunk to receive them.
Reading here (https://xypro.com/secure-database-management/from-zero-to-hero-integrate-hpe-nonstop-with-splunk/) it seems that you can configure Tandem XMA to send syslogs using TCP or UDP protocol, so you have to:
If you didn't configured Splunk syslog receiving before, you can see the following videos and documents:
https://docs.splunk.com/Documentation/SplunkCloud/8.2.2112/Data/HowSplunkEnterprisehandlessyslogdata
https://www.splunk.com/en_us/blog/tips-and-tricks/using-syslog-ng-with-splunk.html
https://www.youtube.com/watch?v=iJ1iBZdXt2o
https://www.youtube.com/watch?v=BQU-bsSCXhk
Ciao.
Giuseppe
Hi @blbr123,
I didn't used Tandem XMA before, but in general, you have to understand how Tandem XMA can send its logs (e.g. syslog or Forwarders) and then configure Splunk to receive them.
Reading here (https://xypro.com/secure-database-management/from-zero-to-hero-integrate-hpe-nonstop-with-splunk/) it seems that you can configure Tandem XMA to send syslogs using TCP or UDP protocol, so you have to:
If you didn't configured Splunk syslog receiving before, you can see the following videos and documents:
https://docs.splunk.com/Documentation/SplunkCloud/8.2.2112/Data/HowSplunkEnterprisehandlessyslogdata
https://www.splunk.com/en_us/blog/tips-and-tricks/using-syslog-ng-with-splunk.html
https://www.youtube.com/watch?v=iJ1iBZdXt2o
https://www.youtube.com/watch?v=BQU-bsSCXhk
Ciao.
Giuseppe
@gcusello Thank you for the response, Actually I already went through the link and was looking to see if there is any additional information available on this.
So looks like I have to onboard it using SC4S only as it's a syslog data.
Hi @blbr123,
syslog isn't the most efficient way to take logs, but it's one of the most used and easier to configure.
Try it and let me know.
Remember that you can ingest syslogs only runtime, this means that, if you need to be sure to take all the logs, you have to configure an High Avalilability architecture: in few words, you need at least two Splunk servers (called Heavy Forwarders) with a Load balancer to take the syslogs.
Ciao.
Giuseppe
@gcusello sure will check the possibilities and try and let you know.
Thank you.
Hi @blbr123,
good for you, let me know and see next time!
Ciao and happy splunking.
Giuseppe
P.S.: Karma Points are appreciated 😉