Getting Data In

In what case would there be a switch to Syslog-NG PE?

Motivator

Do we need Syslog-NG PE?

Currently we are using Syslog-NG OSE. At what case we need to swith to PE?

Tags (2)
0 Karma

Explorer

Hi,

The main differences between syslog-ng PE and OSE:
- Professional support
- Pre-compiled and deeply tested binaries on various platforms
- PE only features like
WEC (Windows Event Collector),
Splunk destination,
Reliable log transport (ALTP),
Tamperproof log storage with logstore

These are the main differences, rest of them can be found on syslog-ng.com

Motivator

Thanks @GerglyBodnar

Let me ask in this way

What is the challenge of using SyslogNG OSE for Splunk? If in case I just need to have some syslogs written to file and forward using UF.

0 Karma

Explorer

If you don't want to utilize Splunk HEC, only using UF then the OSE version also can be a good choice for you. In that case when you have high traffic you have to take care of the load balancing/scaling towards Splunk by yourself.

0 Karma