A new Splunk customer is using syslog to collect data from their network devices on port 514. What is the best practice for ingesting this data into Splunk?
I feel like configuring syslog to send data to multiple indexers could be a good option, but I’m not confident if that’s the most efficient way to handle it.
I remember a practice question where we had to decide between using a forwarder or direct ingestion, and I think the forwarder was preferred for better scalability.
Hmm, I'm a bit unsure about this one. I know it's related to controls, but I'm not sure which of these options is the most direct factor. I'll have to think it through.
I'm a bit confused by this question. I'm not sure if I should be focusing on the model, the training endpoint, the authentication key, or the REST endpoint. Can someone clarify which two parameters are the correct ones to use?
upvoted 0 times
...
Log in to Pass4Success
Sign in:
Report Comment
Is the comment made by USERNAME spam or abusive?
Commenting
In order to participate in the comments you need to be logged-in.
You can sign-up or
login
Isaac
5 months agoNa
5 months agoGiuseppe
6 months agoSalena
6 months agoKayleigh
6 months agoHayley
6 months agoDortha
6 months agoIzetta
6 months agoMelvin
6 months agoEloisa
6 months agoHana
6 months agoFreeman
6 months ago