Receiving syslog with a Splunk forwarder

It is also possible to use Splunk instances to receive the syslog events directly, which then forward the forwarders to the Splunk indexers. This setup might look somewhat like the following diagram:

These interim Splunk forwarder processes can be configured with a large input buffer using the queueSize and persistentQueueSize settings in inputs.conf. Note that these interim forwarders cannot be light forwarders. There are a few advantages to this approach that I can think of:

  • If these Splunk forwarder processes are in the data center with the device producing the events, the forwarder process will ...

Get Implementing Splunk 7 - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.