Getting Data In

syslog-ng to HEC data persistence

splunk_zen
Builder

How would we ensure data persistence/queuing when using Ryan Faircloth's (or a similar script) method to batch the syslog messages using a script rather than the default one message per POST of syslog-ng's http() output ?

Scenario is if there's an 1h network outage between syslog-ng and the HEC HWFs

https://www.rfaircloth.com/2017/02/10/building-perfect-syslog-collection-infrastructure/
0 Karma

hendrick
New Member

Take a look at the native splunk-hec() driver in recent versions of syslog-ng PE.
https://support.oneidentity.com/syslog-ng-premium-edition/7.0.13/technical-documents

Batching and load balancing are built in now.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...