Getting Data In

Best way to use a syslog server and splunk indexer

reswob4
Builder

I have just built a brandy new syslog server. The purpose of this server is to provide a buffer so that instead of sending all syslog traffic directly to my indexers and losing data when I have to restart the indexers for various reasons or the connectivity drops or whatever, all that traffic comes to the syslog server which then gets sent to the indexers. The idea is that this machine would be capable of buffering events if the indexer can't be reached.

So my question is this: Is it best to:

  1. receive remote logs via syslog, write them to a local file/database and then use a universal forwarder to send to indexers
  2. receive remote logs via syslog, write them to a local file/database and then use a heavy forwarder to send to indexers
  3. receive remote logs via syslog, and use syslog to forward again to indexers

Thanks.

Oh, and IF #1, how many universal forwarders can you have on a single machine?

0 Karma
1 Solution

yannK
Splunk Employee
Splunk Employee

The first one is the best if your syslog server is not the indexer.

1 . receive remote logs via syslog, write them to a local file/database and then use a universal forwarder to send to indexers

Otherwise option 4.

4 . receive remote logs via syslog, write them to a local file on the indexers and monitor locally.

View solution in original post

0 Karma

reswob4
Builder

Thanks.

Using #1.

I'm having a weird issue though. I will post another question to deal with that...

0 Karma

yannK
Splunk Employee
Splunk Employee

The first one is the best if your syslog server is not the indexer.

1 . receive remote logs via syslog, write them to a local file/database and then use a universal forwarder to send to indexers

Otherwise option 4.

4 . receive remote logs via syslog, write them to a local file on the indexers and monitor locally.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...