{"id":13621,"date":"2024-02-28T15:03:11","date_gmt":"2024-02-28T09:03:11","guid":{"rendered":"https:\/\/dtasiagroup.com\/?p=13621"},"modified":"2024-06-19T16:11:37","modified_gmt":"2024-06-19T10:11:37","slug":"sending-logs-to-splunk-using-syslog-ng","status":"publish","type":"post","link":"https:\/\/dtasiagroup.com\/vi\/sending-logs-to-splunk-using-syslog-ng\/","title":{"rendered":"Sending logs to Splunk using syslog-ng"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-13622 size-full\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2024\/02\/splunkhatter.jpg-800x400x2.jpg\" alt=\"\" width=\"800\" height=\"400\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Choosing how to collect and forward log messages to Splunk using syslog-ng involves understanding the evolution of support for Splunk within syslog-ng, as well as weighing the pros and cons of different solutions, both open-source and commercial.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>History of Splunk Support in syslog-ng<\/strong><\/p>\n<p>Traditionally, syslog-ng recommended a method involving central log collection using syslog-ng, storing logs locally, and using Splunk forwarders to send them to Splunk. While effective, this approach incurred overhead by requiring installation of multiple applications and duplicating data storage.<\/p>\n<p>The introduction of Splunk HTTP Event Collector (HEC) simplified log forwarding to Splunk. Initially, using the http() destination in syslog-ng was straightforward but lacked encryption and scalability. To address these shortcomings, a Python script was developed for improved security and performance when called via the program() destination.<\/p>\n<p>Over time, syslog-ng&#8217;s http() destination evolved with TLS support, multi-threading, and load balancing. Syslog-ng Premium Edition (PE) introduced splunk-hec(), streamlining Splunk configuration compared to direct http() usage.<\/p>\n<p>Additionally, Splunk released Splunk Connect for Syslog (SC4S), a containerized solution based on syslog-ng. SC4S enhances syslog-ng with additional message parsers, though it offers limited configuration compared to syslog-ng.<\/p>\n<p>Syslog-ng Store Box (SSB), built on syslog-ng PE, offers comprehensive log lifecycle management with a Splunk destination.<\/p>\n<p>Recently, syslog-ng open-source edition (OSE) integrated a Splunk destination into its configuration library (SCL), eliminating the need for custom solutions starting from version 4.2.0.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Choosing the Right Solution<\/strong><\/p>\n<p>The choice between syslog-ng editions depends on various factors:<\/p>\n<ul>\n<li><strong>syslog-ng PE and SSB<\/strong>: Ideal for organizations requiring robust support and exclusive features like compliance and cloud support. They offer commercial-grade reliability and advanced capabilities like LogStore for encrypted log storage.<\/li>\n<li><strong>syslog-ng OSE<\/strong>: Suitable for long-time open-source users or small-scale deployments using the free version of Splunk. It now includes built-in Splunk destination, simplifying configuration without commercial support.<\/li>\n<li><strong>SC4S<\/strong>: Suitable if Splunk is the sole destination and complex filtering isn&#8217;t required. It&#8217;s based on syslog-ng open-source with added parsers, but lacks extensive configuration flexibility.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong>Conclusion<\/strong><\/p>\n<p>Both syslog-ng PE and OSE provide high-performance log collection, parsing, filtering, and versatile destination options, including Splunk. Effective message parsing and filtering reduce license costs by forwarding only relevant logs to each service. Evaluate trial versions of commercial syslog-ng variants or explore the open-source edition to determine the best fit for your environment.<\/p>\n<p>For more details or trials, visit <a href=\"https:\/\/www.syslog-ng.com\/trials\/\" target=\"_new\" rel=\"noreferrer noopener\">syslog-ng trials page<\/a> which also provides access to the syslog-ng GitHub page for the open-source edition.<\/p>\n<p>&nbsp;<\/p>\n<p>Source:\u00a0<a href=\"https:\/\/www.syslog-ng.com\/community\/b\/blog\/posts\/sending-logs-to-splunk-using-syslog-ng\">https:\/\/www.syslog-ng.com\/community\/b\/blog\/posts\/sending-logs-to-splunk-using-syslog-ng<\/a><\/p>\n<p>&nbsp;<\/p>\n<p><strong>Gi\u1edbi thi\u1ec7u v\u1ec1 DT Asia<\/strong><\/p>\n<p>DT Asia \u0111\u01b0\u1ee3c th\u00e0nh l\u1eadp v\u00e0o n\u0103m 2007 v\u1edbi s\u1ee9 m\u1ec7nh r\u00f5 r\u00e0ng l\u00e0 x\u00e2y d\u1ef1ng b\u01b0\u1edbc th\u00e2m nh\u1eadp th\u1ecb tr\u01b0\u1eddng cho c\u00e1c gi\u1ea3i ph\u00e1p b\u1ea3o m\u1eadt CNTT ti\u00ean phong kh\u00e1c nhau t\u1eeb M\u1ef9, Ch\u00e2u \u00c2u v\u00e0 Israel.<\/p>\n<p>Ng\u00e0y nay, DT Asia l\u00e0 nh\u00e0 ph\u00e2n ph\u1ed1i gi\u00e1 tr\u1ecb gia t\u0103ng khu v\u1ef1c v\u1ec1 c\u00e1c gi\u1ea3i ph\u00e1p an ninh m\u1ea1ng, cung c\u1ea5p c\u00e1c c\u00f4ng ngh\u1ec7 ti\u00ean ti\u1ebfn cho c\u00e1c c\u01a1 quan ch\u00ednh ph\u1ee7 tr\u1ecdng \u0111i\u1ec3m v\u00e0 c\u00e1c kh\u00e1ch h\u00e0ng h\u00e0ng \u0111\u1ea7u thu\u1ed9c khu v\u1ef1c t\u01b0 nh\u00e2n, bao g\u1ed3m c\u00e1c ng\u00e2n h\u00e0ng to\u00e0n c\u1ea7u v\u00e0 c\u00e1c c\u00f4ng ty thu\u1ed9c danh s\u00e1ch Fortune 500. Ch\u00fang t\u00f4i c\u00f3 c\u00e1c v\u0103n ph\u00f2ng v\u00e0 \u0111\u1ed1i t\u00e1c kh\u1eafp khu v\u1ef1c Ch\u00e2u \u00c1 - Th\u00e1i B\u00ecnh D\u01b0\u01a1ng nh\u1eb1m th\u1ea5u hi\u1ec3u r\u00f5 h\u01a1n c\u00e1c th\u1ecb tr\u01b0\u1eddng v\u00e0 cung c\u1ea5p c\u00e1c gi\u1ea3i ph\u00e1p mang t\u00ednh b\u1ea3n \u0111\u1ecba h\u00f3a.<\/p>","protected":false},"excerpt":{"rendered":"<p>There are many ways you can collect log messages using syslog-ng and forward them to Splunk. In this blog I collect the history of Splunk support in syslog-ng, and the advantages and disadvantages of various solutions, both open source and commercial.<\/p>","protected":false},"author":11,"featured_media":13622,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56],"tags":[],"class_list":["post-13621","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles"],"_links":{"self":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/13621","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/comments?post=13621"}],"version-history":[{"count":0,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/13621\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media\/13622"}],"wp:attachment":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media?parent=13621"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/categories?post=13621"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/tags?post=13621"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}