Splunk Enterprise

What are the pros and cons of using Splunk as the Syslog server?

BharathKM
New Member

Can we use Splunk as the Syslog server? if Yes then what are the Pros and cons of using Splunk as the Syslog server?

Labels (1)
Tags (1)
0 Karma

skalliger
SplunkTrust
SplunkTrust

Splunk is way too expensive to just use it as a syslog server. You'd rather want a Linux-based system that uses either rsyslog or syslog-ng which collects all logs for you. And the logs that you'll need then go into your Splunk environment.

Another contra, besides the cost, is that Splunk may and will be restarted sometimes. The server that will listen for incoming syslog data will then not be able to receive that data while Splunk restarts. A syslog server itself won't be restarted regularly.

 

Skalli

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!