Splunk Enterprise

How to ask Splunk to get/retrieve a log file?

splunkbee
New Member

Hi,

My log files are stored an a machine. There is no way I can tell this machine to send them somewhere. I must manually go into some directories and pull them all out.
Can Splunk do that for me?

Thanks

0 Karma

woodcock
Esteemed Legend

When you do a "pull" for data instead of a "push", you have to write some glue. You need a Universal Forwarder as a way-station and then you write a script to go to the source machine and pull the data to the UF. You then use traditional means to forward from there, being careful to use the original host for field host (instead of the UF's value).

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...