Deployment Architecture

Planning to have syslog-ng on one of our heavy forwarder

niha1318
New Member

Syslog configuration

we have 2 newly buildup heavy forwarders in our splunk environment, instead of having syslog-ng on separate dedicated servers, we thought of download/install syslog-ng on one of our Heavy Forwarder. is this recommendable? if yes, can someone please send me if there is any documentation??

Thank You,

Tags (1)
0 Karma

ashutoshab
Communicator

It is completely fine if you install Syslog-ng on your Heavy Forwarder. There are advantages to this. I am enlisting a few points below please consider them

  1. Heavy Forwarders need higher resources as compared to Universal Forwarders. Please make sure you have enough resources.
  2. As with Heavy Forwarder, you might not be indexing all the data that is received. A plain HF with no indexing requires less storage. But when we switch to Syslog-ng, the storage requirements increase based on the amount of data we ingest.
  3. We need to take care of the log rotation, in case we have a huge volume of data coming to the Syslog server. If the disk gets full, Syslog server might stop working and we lose in-flight data. Old and Indexed data should be removed / archived on time.
  4. Using Syslog server, it is more convenient to manage data before indexing it in Splunk.

Hope the above points are helpful.

0 Karma

muralikoppula
Communicator

You can configure syslog-ng on Heavy Forwarder but make sure the server should have sufficient resources. Here is the link for configuring syslog-ng with Splunk.

https://www.splunk.com/blog/2016/03/11/using-syslog-ng-with-splunk.html

Hope this helps..

0 Karma
Get Updates on the Splunk Community!

What’s New in Splunk Enterprise 9.4: Tools for Digital Resilience

What’s New in Splunk Enterprise 9.4: Tools for Digital ResilienceTune in to What’s New in Splunk Enterprise ...

Get Schooled with Splunk Education: Explore Our Latest Courses

At Splunk Education, we’re dedicated to providing incredible learning experiences that cater to every skill ...

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL  The Splunk AI Assistant for SPL ...