Getting Data In

Should I create one syslog server and configure all the syslog sources to send logs to that central syslog server?

rashid47010
Communicator

We have different syslog sources.
Should I create one syslog server and configure all the syslog sources to send logs to that central syslog server and then install the UF to read the files from that paths?

Please share some scenarios or Splunk configuration.

0 Karma

rgreer
Path Finder

What you outlined is exactly what we ended up doing in each of our data centers. Kiwi Syslog on a virtual machine with a UF pulling in each log with the correct sourcetype. Our corporate IT guys ended up using Rsyslog on a Redhat VM with a UF as well. Both ended up being cheap, cost effective solutions to our syslog problem.

0 Karma

xpac
SplunkTrust
SplunkTrust

On purpose or not, you ended up doing the best practice for that kind of use case. 😉
Syslog server writing to disk and Splunk monitoring those files is the recommended approach.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...