I am working on a cross platform project here is the scenario:
We have a Linux syslog server currently in place collecting syslogs from all network appliances and UNIX/Linux systems. From this Linux server, all syslogs are then uploaded to a SIEM appliance.
We have an SCOM 2012 server in place running ACS. In the past we had SNARE agents running on all 500 windows server. However, we eliminated the agents.
Since all Windows events are stored in a SQL database on SCOM or ACS server, can we use an OBDC connector to interface with the Linux syslog server running SQL and aggregate the windows event logs to this Linux syslog server?
The goal is to have the windows syslog’s target the Linux syslog server which is the one and only syslog server we need to maintain. However, a colleague brought up this idea of using an OBDC connector and due to my limited knowledge of databases, I was wondering if you guys can shed light on this theory.
Thanks in advance.