Getting Data In

Is it possible to read and monitor Windows server files from a Linux Heavy Forwarder?

reswob4
Builder

I have an environment where it's going to be a hassle to add a new Windows server. However, we have a file on a Windows server we would like to monitor and log. Is it possible to do that from a Linux Heavy Forwarder? Using samba/cifs so we can map the drive?

Or, as this answer implies

( https://answers.splunk.com/answers/27269/using-fschange-to-monitor-files-on-linux-server-from-window... ),

will that cause more problems then it's worth?

Thanks.

0 Karma

adonio
Ultra Champion

Hello,
you can install a windows forwarder on that server and monitor the file and send it straight to your linux splunk heavy forwarder, or directly to the indexer tier
hope it helps

0 Karma

reswob4
Builder

Thanks, but (and I should have mentioned this in the original post) I am not permitted to install a windows forwarder on the windows server. Hence the question about the work around.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...