Abstract

An enterprise infrastructure consists of several devices. The devices emit event notifications representing their current state. The devices without storage such as printers and routers are configured to send the event notifications in the form of syslogs to one or more remote syslog servers over the network. Depending on the size and usage of the enterprise infrastructure, millions of syslogs may be emitted per second. These syslogs are used by the system administrators to detect and address the anomalies in the infrastructure. The system administrators often integrate the syslog servers with Log Analysis tools that offer aggregation, analytics, and visualisation capabilities. Splunk is one such popular tool that can be integrated with syslog servers. This paper proposes an architectural pattern for syslog servers that are to be integrated with Splunk for better performance, scalability and resilience.

Highlights

  • Syslog was developed at University of Barkley, California, USA in the early 80s

  • The following are some of the circumstances in which devices send syslogs: A printer emits a syslog when a print job is scheduled

  • The administrators of today are still dealing with the syslog systems that are built on top of plain User Datagram Protocol (UDP)

Read more

Summary

INTRODUCTION

Syslog was developed at University of Barkley, California, USA in the early 80s. Since it has been the standard logging solution on Unix-like systems. It has been the standard logging solution on Unix-like systems Diskless devices such as network routers and printers use syslog for logging the events on remote servers. The following are some of the circumstances in which devices send syslogs:. A printer emits a syslog when a print job is scheduled. A printer emits a syslog when a print job is finished. A VOIP-based phone emits a syslog when a call is placed. A router emits a syslog when an interface fails to initialise. The syslog protocol is documented in multiple RFCs

RFC 3164
Syslog-ng
THE SYSLOG SERVER COMPONENTS
SPLUNK
Splunk Enterprise Server
Splunk Forwarder
Splunk as the Syslog Server
THE PROPOSED ARCHITECTURE
CONCLUSION
Full Text
Paper version not known

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call

Disclaimer: All third-party content on this website/platform is and will remain the property of their respective owners and is provided on "as is" basis without any warranties, express or implied. Use of third-party content does not indicate any affiliation, sponsorship with or endorsement by them. Any references to third-party content is to identify the corresponding services and shall be considered fair use under The CopyrightLaw.