Getting Data In

syslog-ng to HEC data persistence

splunk_zen
Builder

How would we ensure data persistence/queuing when using Ryan Faircloth's (or a similar script) method to batch the syslog messages using a script rather than the default one message per POST of syslog-ng's http() output ?

Scenario is if there's an 1h network outage between syslog-ng and the HEC HWFs

https://www.rfaircloth.com/2017/02/10/building-perfect-syslog-collection-infrastructure/
0 Karma

hendrick
New Member

Take a look at the native splunk-hec() driver in recent versions of syslog-ng PE.
https://support.oneidentity.com/syslog-ng-premium-edition/7.0.13/technical-documents

Batching and load balancing are built in now.

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...