Getting Data In

Getting logs in splunk using log location address

accuser123
New Member

Hi! I am a new to Splunk. I have an application on a linux server that produces logs in log4j format. I want to receive analysethese logs.

I have installed Splunk Web on Windows . But I want to receive continuous log data from server without using forwarder. So is there any way by which I can get the log by just using the path of the location where logs are getting generated. if it can be done please tell how I can do that.

Thanks in Advance
-Rohit

Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Splunk and your data are on two different platforms. That's a problem for which the Universal Forwarder was designed. If you can't or won't use a forwarder then you're limited to writing the logs to shared storage (perhaps using something like Samba) that your Splunk server can read.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk and your data are on two different platforms. That's a problem for which the Universal Forwarder was designed. If you can't or won't use a forwarder then you're limited to writing the logs to shared storage (perhaps using something like Samba) that your Splunk server can read.

---
If this reply helps you, Karma would be appreciated.
0 Karma

accuser123
New Member

Thanks for the answer. However i didn't got what i was looking for but i am satisfied with the answer.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...