All Apps and Add-ons

TCP Input or SQL for Websense Security Logs

aelliott
Motivator

To feed logs from Websense to Splunk, which would be ideal and why?
As a TCP Input
From MSSQL

If Splunk server goes down, will logs be lost using the TCP input?

Tags (3)
0 Karma
1 Solution

aelliott
Motivator

Since I have seen some posts that say that SQL Logs are the way to go, and TCP inputs have the possibility of losing data if the splunk server were to go down. I am going to say that the better way is through MSSQL as it will pick up where it left off.

View solution in original post

0 Karma

aelliott
Motivator

Since I have seen some posts that say that SQL Logs are the way to go, and TCP inputs have the possibility of losing data if the splunk server were to go down. I am going to say that the better way is through MSSQL as it will pick up where it left off.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...