Splunk Enterprise

What are the pros and cons of using Splunk as the Syslog server?

BharathKM
New Member

Can we use Splunk as the Syslog server? if Yes then what are the Pros and cons of using Splunk as the Syslog server?

Labels (1)
Tags (1)
0 Karma

skalliger
Motivator

Splunk is way too expensive to just use it as a syslog server. You'd rather want a Linux-based system that uses either rsyslog or syslog-ng which collects all logs for you. And the logs that you'll need then go into your Splunk environment.

Another contra, besides the cost, is that Splunk may and will be restarted sometimes. The server that will listen for incoming syslog data will then not be able to receive that data while Splunk restarts. A syslog server itself won't be restarted regularly.

 

Skalli

0 Karma
Get Updates on the Splunk Community!

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...

IM Landing Page Filter - Now Available

We’ve added the capability for you to filter across the summary details on the main Infrastructure Monitoring ...

Dynamic Links from Alerts to IM Navigators - New in Observability Cloud

Splunk continues to improve the troubleshooting experience in Observability Cloud with this latest enhancement ...