Getting Data In

How can I keep Syslog from reading and storing data?


In syslog ng I didn’t want to read the data and store the data , how do you do that?

Labels (1)
0 Karma


Here is an example of syslog-ng configuration that stores the data on disk for Splunk to read. You will need to manage the data's retention with something like logrotate.

Here is an example that uses syslog-ng and HEC, where no data is stored on the syslog server.

You could also use the Splunk App for Syslog (SC4S)


0 Karma
Get Updates on the Splunk Community!

Synthetic Monitoring: Not your Grandma’s Polyester! Tech Talk: DevOps Edition

Register today and join TekStream on Tuesday, February 28 at 11am PT/2pm ET for a demonstration of Splunk ...

Instrumenting Java Websocket Messaging

Instrumenting Java Websocket MessagingThis article is a code-based discussion of passing OpenTelemetry trace ...

Announcing General Availability of Splunk Incident Intelligence!

Digital transformation is real! Across industries, companies big and small are going through rapid digital ...