Hi,
What is the best practice when looking at syslogs:
What are the pluses and minutes of each option.
cheers,
ski
Hi,
I would say that if you can be bothered to configure your syslog-server to split incoming data into separate files you'd be a lot better off. Since the syslog daemon is aware of the originating IP/hostname as well as facility, you can build a directory structure like /var/log/my_syslog/<hostname>/<ip-address>.log
or something similar.
This is more certain than relying on Splunk being able to parse out the hostname from each event, which is default splunk behaviour for the syslog
sourcetype. This will work in almost all cases, but I've seen network appliances that log without a space after the hostname, resulting in host
s like
switch01snmpUtil
switch01snmpMgmt
switch01somethingElse
Thus you'll get a new host for each type of message from a single device, which is not so good, and unfortunately hard/impossible to correct on the splunk server.
Hope this helps,
Kristian