Getting Data In

How to monitor HAproxy logs of server in Splunk

rahul2gupta
Path Finder

Hi @gcusello ,

Could you please help me to monitor HA proxy logs of server in Splunk. What should be the steps that needs to be carried out.

Also user is saying that "The HAProxy container is set up with rsyslog, using the omfwd module to forward traffic to the relevant IP address that has been set up in the config."

Regards,

Rahul

 

Labels (3)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @rahul2gupta,

if your proxies send their logs to an rsyslog server, the best approach is to have two rsyslog servers with Splunk Universal Forwarder.

Then you need a Load Balancer to distribute traffic between the two rsyslog servers and manage fail tolerance.

The Load Balancer could be an Hardware Load Balancer (better) or also a DNS configuration to have a virtual address that send logs to the two rsyslog servers.

Then Universal Forwarders reads log files and send logs to Splunk.

Otherwise, you can also use two Heavy Forwarders and use their capabilities to ingest syslogs instead of rsyslog server.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @rahul2gupta,

if your proxies send their logs to an rsyslog server, the best approach is to have two rsyslog servers with Splunk Universal Forwarder.

Then you need a Load Balancer to distribute traffic between the two rsyslog servers and manage fail tolerance.

The Load Balancer could be an Hardware Load Balancer (better) or also a DNS configuration to have a virtual address that send logs to the two rsyslog servers.

Then Universal Forwarders reads log files and send logs to Splunk.

Otherwise, you can also use two Heavy Forwarders and use their capabilities to ingest syslogs instead of rsyslog server.

Ciao.

Giuseppe

PickleRick
SplunkTrust
SplunkTrust

I'd have to double-check it but I think DNS-based load balancing will not work with rsyslog.

Anyway, if the HAproxy containers send normal syslog, it just boils down to a typical case of receiving syslog events - be it with rsyslog or sc4s or whatever other solution you want.

Oh, and there is an add-on for HAproxy so the logs should get parsed properly almost out of the box (unless the containerized haproxy massacres them in any way).

0 Karma

rahul2gupta
Path Finder

Thanks @gcusello !

0 Karma
Get Updates on the Splunk Community!

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Splunk Education Goes to Washington | Splunk GovSummit 2024

If you’re in the Washington, D.C. area, this is your opportunity to take your career and Splunk skills to the ...