A new Splunk customer is using syslog to collect data from their network devices on port 514. What is the best practice for ingesting this data into Splunk?
I feel like configuring syslog to send data to multiple indexers could be a good option, but I’m not confident if that’s the most efficient way to handle it.
I remember a practice question where we had to decide between using a forwarder or direct ingestion, and I think the forwarder was preferred for better scalability.
Hmm, I'm a bit unsure about this one. I know it's related to controls, but I'm not sure which of these options is the most direct factor. I'll have to think it through.
I'm a bit confused by this question. I'm not sure if I should be focusing on the model, the training endpoint, the authentication key, or the REST endpoint. Can someone clarify which two parameters are the correct ones to use?
upvoted 0
times
...
Log in to Pass4Success
Sign in:
Report Comment
Is the comment made by USERNAME spam or abusive?
Commenting
In order to participate in the comments you need to be logged-in.
You can sign-up or
login
Isaac
7 months agoNa
7 months agoGiuseppe
7 months agoSalena
7 months agoKayleigh
7 months agoHayley
8 months agoDortha
8 months agoIzetta
8 months agoMelvin
8 months agoEloisa
8 months agoHana
8 months agoFreeman
8 months ago