A new Splunk customer is using syslog to collect data from their network devices on port 514. What is the best practice for ingesting this data into Splunk?
I feel like configuring syslog to send data to multiple indexers could be a good option, but I’m not confident if that’s the most efficient way to handle it.
I remember a practice question where we had to decide between using a forwarder or direct ingestion, and I think the forwarder was preferred for better scalability.
Hmm, I'm a bit unsure about this one. I know it's related to controls, but I'm not sure which of these options is the most direct factor. I'll have to think it through.
I'm a bit confused by this question. I'm not sure if I should be focusing on the model, the training endpoint, the authentication key, or the REST endpoint. Can someone clarify which two parameters are the correct ones to use?
upvoted 0 times
...
Log in to Pass4Success
Sign in:
Report Comment
Is the comment made by USERNAME spam or abusive?
Commenting
In order to participate in the comments you need to be logged-in.
You can sign-up or
login
Isaac
4 months agoNa
4 months agoGiuseppe
4 months agoSalena
4 months agoKayleigh
4 months agoHayley
5 months agoDortha
5 months agoIzetta
5 months agoMelvin
5 months agoEloisa
5 months agoHana
5 months agoFreeman
5 months ago