Deployment Architecture

Planning new Splunk Architecture- placing Syslog-ng on same machine as Heavy Forwarder okay?

ojay
Path Finder

Hi,

I'm planning a new splunk architecture and was thinking about placing the syslog-ng on the same virtual machine as the Heavy Forwarder to read the files locally.

  • How will a large data volume impact the performance or stability?
  • What do i need to consider for memory and diskspace if i combine?
  • When is this advised to seperate to a dedicated syslog-ng server?
  • Will a dedicated syslog-ng server allow for more syslog traffic?
  • Would it be beneficial to install a Universal Forwarder on the HF for local file reading? Is it more advised for better data buffering?

Thank you,

Jay

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...