March 2018
Beginner to intermediate
576 pages
13h 29m
English
For very small installations, it may be acceptable to have your Splunk server listen directly for syslog events. This installation looks essentially like the following diagram:

On the Splunk indexer, you would create an input for syslog, listening on udp or tcp. The inputs.conf configuration would look like:
[udp://514] sourcetype = syslog
The advantage of this approach is its simplicity. The major caveat is that, if the Splunk process is down or busy for some reason, you will lose messages. Reasons for dropped events could include a heavy system load, large queries, a slow disk, network problems, ...
Read now
Unlock full access