Hi, I have a requirement to store the raw logs collected from the endpoints. So I am planning to introduce a syslog server between endpoint and elasticsearch. The general deployment would be,
Log sources -> rsyslog/syslog-ng -> elastic
I am planning to have a 3node elastic cluster. So my doubts are:
- which syslog server is better: syslog-ng or rsyslog?
- Can I install the syslog server in one of the nodes itself?
Would be grateful if you can share your inputs.