Getting Data In

What are best practices for logging to splunk?

shanemhartley
New Member

We have logs that are written to

/var/log

/var/log/audit

 

We need to keep these for 365 days, and want to ensure that we are following best practices, is there a set of configuration settings we can follow to ensure we're following best practices?

Ultimately, we want to ensure we have log retention, and that /var/log is not a cluttered mess. 

 

Thank you!

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @shanemhartley ,

ingestion in Splunk is usually done using a Technical Add-On , in your case the Splunk_TA_nix (https://splunkbase.splunk.com/app/833).

You have to install this add-on on the Universal Forwarder enabling the input stanzas you need.

If you want to store these logs in a defined index (instead of main), you have also to add to each enabled input stanza the option:

index = <your_index>

Then you have to install this add-on also on your Search Head or your Stand Alone Splunk Server.

In this way you have the logs correctly parsed and usable.

For more infos see at https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/Getstartedwithgettingdatain and there are also more videos.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk &#43; Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...