Re: rsyslog host

2018-12-17 Thread Victor Montoya
Hello, .This is Victor, I know this is off topic but I think I left my black IBM ThinkPad at last week's PLUG Chirstmass party in the community room. I already checksd with the police and they said they didn't have it. I was wondering if anyone picked it up? Victor Montoya Sent from

Re: rsyslog host

2018-12-14 Thread James Mcphee
https://github.com/balabit/syslog-ng though I've also switched to rsyslog. there have been too many fiddly bits when using the advanced functions of syslog-ng for me to trust it. On Fri, Dec 14, 2018 at 8:54 AM Snyder, Alexander J < a...@misteralexander.com> wrote: > They must be using a fork

Re: rsyslog host

2018-12-14 Thread Snyder, Alexander J
They must be using a fork or something. In a recent meeting it was brought up that their software base hasn't been updated since 2007. I'll definitely dive deeper in to that! Thanks! Thanks, Alexander. Sent from my Samsung Galaxy S8+ On Fri, Dec 14, 2018, 07:08 Are you sure syslog-ng is not

Re: rsyslog host

2018-12-14 Thread amit
Are you sure syslog-ng is not updated in years ? Latest release is 3.19.1 released 23 hours ago. Wonder if I am mistaken. Get Outlook for Android On Fri, Dec 14, 2018 at 6:42 AM -0700, "Snyder, Alexander J" wrote: We're currently using syslog-ng and are moving away from it

Re: rsyslog host

2018-12-14 Thread Snyder, Alexander J
We're currently using syslog-ng and are moving away from it as the project hasn't been updated in years (obscurity is not security). We're collecting with rsyslog and sending to Splunk for search and visualization. Right now we're only testing with rsyslog and only have it configured on a single

Re: rsyslog host

2018-12-12 Thread Amit Nepal
I suggest looking into syslog-ng for centralized log server. Clients can use rsyslog for unix and nxlog for windows.  Syslog-ng is scalable, high speed and provides a lot of features for parsing, alerting, co-relating etc. You can Use Syslog-ng for central log collection, send it to

Re: rsyslog host

2018-12-12 Thread Michael Butash
Size/quantity matters, significantly here. I'd start of with your expected GiB per day, or messages per second (mps). Factor in some per log kb standard sizing, come up with both mps/per day, and you can probably work back from there in terms of required disk iops to write them (or buy a product

Re: rsyslog host

2018-12-12 Thread James Mcphee
Centralized logging can be a complex subject to discuss. One of the more useful things to talk about is the number of messages per second you'll be processing. There is tuning to rsyslog that you should do if you're going to be running it as a receiver and expect a reasonably large number of

Re: rsyslog host

2018-12-12 Thread Stephen Partington
How many data sources are you looking at? 1000 1? On Wed, Dec 12, 2018, 2:10 PM Snyder, Alexander J Looking for suggestions on what kind of physical resources would suggested > to building a central logging server for an enterprise company. > > rsyslog is new for the company, so we're

rsyslog host

2018-12-12 Thread Snyder, Alexander J
Looking for suggestions on what kind of physical resources would suggested to building a central logging server for an enterprise company. rsyslog is new for the company, so we're looking to "do it right" from the ground up. How many hosts should be needed to log networking and storage