Getting Data In

Critical Syslog Server Tricks

aydinmo
Explorer

Hi all,

I have a large environment to deploy Splunk cloud and trying to leverage the syslog server (Rsyslog) in front of a load balancer, with UF on top.

As per my research, I have found a wonderful document which automates the inputs.conf and props.conf creation based on an excel sheet, relying on separation based on devices hostnames.

The link for documentation is here: https://conf.splunk.com/files/2017/slides/the-critical-syslog-tricks-that-no-one-seems-to-know-about...

I'm wondering if anyone has used the provided scripts for this automation? I couldn't find any explanation on how the python scripts work?

link to gitlab: https://gitlab.com/rationalcyber/splunk_syslog_inputs

link to script: https://gitlab.com/rationalcyber/splunk_syslog_inputs/-/tree/master/src

Thanks in advance!

0 Karma

evilgeorge
Explorer

@aydinmo did you get this resolved?  I'm one of the presenters of that 2017 .conf talk; please let me know if there were any hurdles you couldn't get past.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...