Getting Data In

What is included in Linux syslog?

vnguyen46
Contributor

Hi,

On Linux Splunk servers, my system admin set this record in remotesyslog.conf
. @@syslog-zone40.uth.tmc.edu:1514

Anyone knows what type of logs this setup is send to Splunk HF? (os log and application log, or anything else)

Thank you,

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

Probably same events are sent also to local /var/log/messages and other files under /var/log directory? You should start to look there.

Ismo

0 Karma
Get Updates on the Splunk Community!

Machine Learning - Assisted Adaptive Thresholding

Let’s talk thresholding. Have you set up static thresholds? Tired of static thresholds triggering false ...

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

  Ready to master Kubernetes and cloud monitoring like the pros?Join Splunk’s Growth Engineering team for an ...

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...