Getting Data In

In what case would there be a switch to Syslog-NG PE?

ansif
Motivator

Do we need Syslog-NG PE?

Currently we are using Syslog-NG OSE. At what case we need to swith to PE?

Tags (2)
0 Karma

GergelyBodnar
Explorer

Hi,

The main differences between syslog-ng PE and OSE:
- Professional support
- Pre-compiled and deeply tested binaries on various platforms
- PE only features like
WEC (Windows Event Collector),
Splunk destination,
Reliable log transport (ALTP),
Tamperproof log storage with logstore

These are the main differences, rest of them can be found on syslog-ng.com

ansif
Motivator

Thanks @GerglyBodnar

Let me ask in this way

What is the challenge of using SyslogNG OSE for Splunk? If in case I just need to have some syslogs written to file and forward using UF.

0 Karma

GergelyBodnar
Explorer

If you don't want to utilize Splunk HEC, only using UF then the OSE version also can be a good choice for you. In that case when you have high traffic you have to take care of the load balancing/scaling towards Splunk by yourself.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...