Getting Data In

Can splunk read data from unix stream socket?

gots
Path Finder

Is it possible to get data in splunk from unix stream socket?
Not tcp\udp socket, but socket like this - https://en.wikipedia.org/wiki/Berkeley_sockets

For example syslog-ng have this feature.

Tags (1)
0 Karma
1 Solution

brolo
Explorer

Why not use syslog-ng as a go between?
See this link: httpss://www.splunk.com/blog/2016/03/11/using-syslog-ng-with-splunk.html

View solution in original post

woodcock
Esteemed Legend

Splunk needs more tuning, upgrades and restarts than does syslog-ng so if you go directly to Splunk, without a buffer capability on the sending side, you will have far more data loss. You can update yslog-ng configurations with SIGHUP without a restart or data outage. You cannot do that with Splunk. Use syslog-ng.

0 Karma

woodcock
Esteemed Legend
0 Karma

felipesewaybric
Contributor
0 Karma

brolo
Explorer

Why not use syslog-ng as a go between?
See this link: httpss://www.splunk.com/blog/2016/03/11/using-syslog-ng-with-splunk.html

vidhyaArumalla
Path Finder

I agree with @brolo

0 Karma

gots
Path Finder

I already done it with syslog-ng, but it seems that will be better do not create additional entities for simple task.

Python script also can help, but it is not ideal solution.

I had little hope that something miss in documentation.

Thank you all.

0 Karma

sjodle
Path Finder

I also agree. Alternatively, you could write a Bash or Python scripted input that reads the socket to stdout.

0 Karma
Get Updates on the Splunk Community!

Celebrating the Winners of the ‘Splunk Build-a-thon’ Hackathon!

We are thrilled to announce the winners of the Splunk Build-a-thon, our first-ever hackathon dedicated to ...

Why You Should Register for Splunk University at .conf25

Level up before .conf25 even begins Splunk University is back in Boston, September 6–8, and it’s your chance ...

Building Splunk proficiency is a marathon, not a sprint

Building Splunk skills is a lot like training for a marathon. It’s about consistent progress, celebrating ...