All Apps and Add-ons

TCP Input or SQL for Websense Security Logs

aelliott
Motivator

To feed logs from Websense to Splunk, which would be ideal and why?
As a TCP Input
From MSSQL

If Splunk server goes down, will logs be lost using the TCP input?

Tags (3)
0 Karma
1 Solution

aelliott
Motivator

Since I have seen some posts that say that SQL Logs are the way to go, and TCP inputs have the possibility of losing data if the splunk server were to go down. I am going to say that the better way is through MSSQL as it will pick up where it left off.

View solution in original post

0 Karma

aelliott
Motivator

Since I have seen some posts that say that SQL Logs are the way to go, and TCP inputs have the possibility of losing data if the splunk server were to go down. I am going to say that the better way is through MSSQL as it will pick up where it left off.

0 Karma
Get Updates on the Splunk Community!

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...

From Alert to Resolution: How Splunk Observability Helps SREs Navigate Critical ...

It's 3:17 AM, and your phone buzzes with an urgent alert. Wire transfer processing times have spiked, and ...