Splunk Connect for Syslog (SC4S)
Key facts
Links
Sourcetypes
Sourcetype and Index Configuration
Filter type
SC4S events and metrics are generated automatically and no specific ports or filters need to be configured for the collection of this data.
Setup and Configuration
- The default index used for sc4s metrics will be “_metrics”
- Metrics data is collected by default as traditional events; use of Splunk Metrics is enabled by an opt-in set by the variable
SC4S_DEST_SPLUNK_SC4S_METRICS_HEC
. See the “Options”
section below for details.
Options
Verification
SC4S will generate versioning events at startup. These startup events can be used to validate HEC is set up properly on the Splunk side.
index=<asconfigured> sourcetype=sc4s:events | stats count by host
Metrics can be observed via the “Analytics–>Metrics” navigation in the Search and Reporting app in Splunk.
- NOTE: The presentation of metrics is undergoing active development; the delivery of metrics is currently considered an experimental feature.