Syslog (rsyslog or syslog-ng) is used by almost 99% of Linux based Splunk installations for collection of data especially from network devices where the data is transient. Key things to remember while collecting these logs are
Link to git code: logrotate.d
- To store the log using syslog and forward to other systems if required.
- Store them in a well formatted directory structure.
- Direct streaming to Splunk is not preferred as restart of Splunk causes problem
Link to git code: logrotate.d
Loading ....
- Delaycompress is required, so that log files are NOT rotated while splunk is reading it
- While collecting into splunk discard any .gz extensions
Ensure size is specified to a feasible value
"super....!!!
ReplyDeleteDigital Marketing Training Course in Chennai | Digital Marketing Training Course in Anna Nagar | Digital Marketing Training Course in OMR | Digital Marketing Training Course in Porur | Digital Marketing Training Course in Tambaram | Digital Marketing Training Course in Velachery
"