Getting Data In

How do I set up Splunk Enterprise Linux to ingest Windows logs that are not part of the universal forwarder install?

Sarmbrister
Path Finder

I am new to Splunk. The main admin left a few months ago and I have taken over with little to no training. A colleague wants to ingest Windows Event Lync service logs and I have no idea how to get it to work, but he has installed the universal forwarder. Can some one help me out? I have read the documents on inputs.conf and still having issues. Need help fellow Splunkers!

Thanks in advance.

0 Karma
1 Solution

alacercogitatus
SplunkTrust
SplunkTrust

Aye, my friend. I've heard many a tall tale of such mutiny. If only the loyalty of the first mate was to be held with integrity! Methinks you have come to the right place. The Conf of Inputs (a heavily visited island in these here parts) does in fact contain the basics of the information you seek! First, seek ye the location of the Logs of Lync. Knowing the location of such Logs is paramount to properly mining them. Second, configure the Conf of Inputs ( inputs.conf ) to use a stanza of monitor, consult ye the docs mentioned by yourself on proper syntax. Upon correct placement of this conf (on the forwarder), restart said Agent of Splunk (forwarder on the Windows box). A sample of said configuration booty shall be listed herein, as we in the Conf of Splunk tend to do. Avast! I see the shores that contain this Lake of Data! Query forthwith ye questions!

[monitor://C:\\Windows\\System32\\SomePathtoLync]
sourcetype = lync_server

View solution in original post

alacercogitatus
SplunkTrust
SplunkTrust

Aye, my friend. I've heard many a tall tale of such mutiny. If only the loyalty of the first mate was to be held with integrity! Methinks you have come to the right place. The Conf of Inputs (a heavily visited island in these here parts) does in fact contain the basics of the information you seek! First, seek ye the location of the Logs of Lync. Knowing the location of such Logs is paramount to properly mining them. Second, configure the Conf of Inputs ( inputs.conf ) to use a stanza of monitor, consult ye the docs mentioned by yourself on proper syntax. Upon correct placement of this conf (on the forwarder), restart said Agent of Splunk (forwarder on the Windows box). A sample of said configuration booty shall be listed herein, as we in the Conf of Splunk tend to do. Avast! I see the shores that contain this Lake of Data! Query forthwith ye questions!

[monitor://C:\\Windows\\System32\\SomePathtoLync]
sourcetype = lync_server

Sarmbrister
Path Finder

Apologize for the late response but that is the BEST answer ever purely for the pirate lingo lol. I have visited this and everything looks like it has been configured right I think part of the issue is that the UF on the windows server is configured for port 9997 instead of 8089. Also I have training in a few weeks and will be at the splunk .conf2015 getting my admin cert so will no longer be a newbie floating in the water but captaining my own ship :D. Thanks again will let you know how everything works out.

Sarmbrister
Path Finder

Worked like a charm! Thanks again Captain.

0 Karma

ChrisG
Splunk Employee
Splunk Employee

Great answer. I think, there near the end, you meant to say "restarrrrrrrt."

Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...