Getting Data In

Recommended R-Syslog equivalent collector for Windows systems.

offspringinc
Engager

Hello,

We have a relatively small network on a remote location that needs to forward logs onto our Splunk Instance, this remote system has particularly low bandwidth per its location.

During our Splunk original architecture call we were advised to setup a syslog collector on this remote network, and setup a scheduled time were logs can be forwarded to the Main Splunk instance for indexing with the idea being setting this task for overnight hours.

Since ALL systems are Windows based in this remote location, the current question we face is, in your experience - Which is the preferred syslog collector for Windows that will easily integrate with Splunk?
is Syslog-NG the best/most common application for this task?

thank you,

offspringinc
Engager

Yes, that may be a good option and because our limited bandwidth is our biggest challenge, to the tune of 1mb up/down rural and unsteady speeds we really need to limit log forwarding to a specific time of night.

Another point I forgot to note is that we'll be 'eventually' adding networking devices such as Firewall, Network Switches, and a VPN appliance, these will need a syslog server.
We use R-Syslog on our parent network, and for that reason we're looking at alternatives that have worked well for you guys to use with Splunk from a Windows System, unfortunately standing up a Linux server is not an option in this environment.

Any other syslog servers recommendations welcomed.

Thank you folks.

0 Karma

mydog8it
Builder

Perhaps you should consider using Windows Event Forwarding to a local server (https://docs.microsoft.com/en-us/advanced-threat-analytics/configure-event-collection) and use a Splunk forwarder to send the logs to your Splunk instance. To meet your need to send the logs off-hours, write a powershell script to enable/disable splunkd as required to meet your transmission requirements.

isoutamo
SplunkTrust
SplunkTrust

Hi

If all those hosts are windows then maybe the easiest way is put one or more heavy/universal forwarders there as “gateway forwarder”. Then point all other UFs to send to those and those relay events to your main site.

R. Ismo

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...