Hi at all,
I'm trying to get Avamar logs by syslog (UDP).
The problem is that every time Avamar sends an event log, I don't receive in Splunk the last event, but the previous; to have the last event Avamar has to generate a new event.
In other words there is a queue problem.
I need to understand if the problem is Avamar (probably but I'm not sure) or splunk configuration.
In the second case, it'a a problem of mine!
Has anyone encountered this problem?
Thank you in advance.
Bye.
Giuseppe
Best way to get logs from Avamar is to get data from it's back-end PostgreSQL database using DB-Connect or custom scripts. That's how we are doing it.
@nabeel652 : Could you please let me know the steps required for this integration.
Hi nabeel652,
I'm not so sure about the problem because I had it two years ago and I didn't solved it!
Anyway, I activate syslogs on Avamar and I received them in Splunk, no particular activities.
Bye.
Giuseppe
@gcusello : Just checking with @nabeel652 on his comment on best way from postgresSQL.
Hello, Can somebody share more details on integrations with Avamar.