adom, multi tenancy, syslog
Hi all
I'd like to know if is it possible to configure the FAZ this way :
We manage a bunch of devices ( switches, windows, apc ... ) from multiple companies; these devices send syslog ( or syslog-like ) messages ( actually, admin logins and logouts ) to a single splunk collector, splunk organizes them by company ( in db called "indexes" ) ; these indexes isolate company devices, so every company can only see theyr devices, providing multitenancy; no or very little processing is required on these data, they are just stored for 2-3 months and then discarded, or dumped to the owner in csv format.
My objective is to get rid of a dedicated ( and very underused ) instance of splunk and store the logs in the already used FAZ, with the same constraints .
Is someone using a similar configuration, or knows is it possible ?
TIA
Arcre
