Deployment Architecture

Planning new Splunk Architecture- placing Syslog-ng on same machine as Heavy Forwarder okay?

ojay
Path Finder

Hi,

I'm planning a new splunk architecture and was thinking about placing the syslog-ng on the same virtual machine as the Heavy Forwarder to read the files locally.

  • How will a large data volume impact the performance or stability?
  • What do i need to consider for memory and diskspace if i combine?
  • When is this advised to seperate to a dedicated syslog-ng server?
  • Will a dedicated syslog-ng server allow for more syslog traffic?
  • Would it be beneficial to install a Universal Forwarder on the HF for local file reading? Is it more advised for better data buffering?

Thank you,

Jay

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...