Getting Data In

How can I keep Syslog from reading and storing data?

Rah
Loves-to-Learn

In syslog ng I didn’t want to read the data and store the data , how do you do that?

Labels (1)
0 Karma

chaker
Contributor

Here is an example of syslog-ng configuration that stores the data on disk for Splunk to read. You will need to manage the data's retention with something like logrotate.
https://www.splunk.com/en_us/blog/tips-and-tricks/using-syslog-ng-with-splunk.html

Here is an example that uses syslog-ng and HEC, where no data is stored on the syslog server.
https://www.splunk.com/en_us/blog/tips-and-tricks/syslog-ng-and-hec-scalable-aggregated-data-collect...

You could also use the Splunk App for Syslog (SC4S)

https://splunkbase.splunk.com/app/4740/

https://splunk.github.io/splunk-connect-for-syslog/main/

 

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...