Hi,
I'm planning a new splunk architecture and was thinking about placing the syslog-ng on the same virtual machine as the Heavy Forwarder to read the files locally.
- How will a large data volume impact the performance or stability?
- What do i need to consider for memory and diskspace if i combine?
- When is this advised to seperate to a dedicated syslog-ng server?
- Will a dedicated syslog-ng server allow for more syslog traffic?
- Would it be beneficial to install a Universal Forwarder on the HF for local file reading? Is it more advised for better data buffering?
Thank you,
Jay