Getting Data In

What are best practices for logging to splunk?

shanemhartley
New Member

We have logs that are written to

/var/log

/var/log/audit

 

We need to keep these for 365 days, and want to ensure that we are following best practices, is there a set of configuration settings we can follow to ensure we're following best practices?

Ultimately, we want to ensure we have log retention, and that /var/log is not a cluttered mess. 

 

Thank you!

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @shanemhartley ,

ingestion in Splunk is usually done using a Technical Add-On , in your case the Splunk_TA_nix (https://splunkbase.splunk.com/app/833).

You have to install this add-on on the Universal Forwarder enabling the input stanzas you need.

If you want to store these logs in a defined index (instead of main), you have also to add to each enabled input stanza the option:

index = <your_index>

Then you have to install this add-on also on your Search Head or your Stand Alone Splunk Server.

In this way you have the logs correctly parsed and usable.

For more infos see at https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/Getstartedwithgettingdatain and there are also more videos.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

The Payment Operations Wake-Up Call: Why Financial Institutions Can't Afford ...

The same scenario plays out across financial institutions daily. A payment system fails at 11:30 AM on a busy ...

Make Your Case: A Ready-to-Send Letter for Getting Approval to Attend .conf25

Hello Splunkers, Want to attend .conf25 in Boston this year but not sure how to convince your manager? We've ...

Community Spotlight: A Splunk Expert's Journey

In the world of data analytics, some journeys leave a lasting impact not only on the individual but on the ...