Syslog configuration
we have 2 newly buildup heavy forwarders in our splunk environment, instead of having syslog-ng on separate dedicated servers, we thought of download/install syslog-ng on one of our Heavy Forwarder. is this recommendable? if yes, can someone please send me if there is any documentation??
Thank You,
It is completely fine if you install Syslog-ng on your Heavy Forwarder. There are advantages to this. I am enlisting a few points below please consider them
Hope the above points are helpful.
You can configure syslog-ng on Heavy Forwarder but make sure the server should have sufficient resources. Here is the link for configuring syslog-ng with Splunk.
https://www.splunk.com/blog/2016/03/11/using-syslog-ng-with-splunk.html
Hope this helps..