Skip to content
Discussion options

You must be logged in to vote

@jfmatth , and anyone else checking out this thread. If you create a UDP input for syslog you can then create a load balancer service to route that traffic to the Splunk pod. The issue I've found is that some syslog clients don't include their information, so you'll just see the load balancer's address as the source host. The only solution to this I'm aware of is to put another syslog server (syslog-ng/sc4s) in between the clients and the load balancer.

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@jfmatth
Comment options

@devinslick
Comment options

Answer selected by jfmatth
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants