Getting Data In

In what case would there be a switch to Syslog-NG PE?

ansif
Motivator

Do we need Syslog-NG PE?

Currently we are using Syslog-NG OSE. At what case we need to swith to PE?

Tags (2)
0 Karma

GergelyBodnar
Explorer

Hi,

The main differences between syslog-ng PE and OSE:
- Professional support
- Pre-compiled and deeply tested binaries on various platforms
- PE only features like
WEC (Windows Event Collector),
Splunk destination,
Reliable log transport (ALTP),
Tamperproof log storage with logstore

These are the main differences, rest of them can be found on syslog-ng.com

ansif
Motivator

Thanks @GerglyBodnar

Let me ask in this way

What is the challenge of using SyslogNG OSE for Splunk? If in case I just need to have some syslogs written to file and forward using UF.

0 Karma

GergelyBodnar
Explorer

If you don't want to utilize Splunk HEC, only using UF then the OSE version also can be a good choice for you. In that case when you have high traffic you have to take care of the load balancing/scaling towards Splunk by yourself.

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...