Getting Data In

How do I forward logs from a network/shared location on a Windows machine to Splunk?

ppanchal
Path Finder

I have installed a universal forwarder on the Windows machine, but the actual logs are getting generated at a shared location.

How do I get these logs forwarded to Splunk?

Logs generated locally to the machine (C:\test) are getting forwarded to Splunk.

Any help is appreciated.

0 Karma

maciep
Champion

you should be able to use the unc path to the share (eg \server\share\app.log), but whatever account splunk runs as would need read permissions to that share. For example, if your uf runs as system, then the computer account would need to be given read perms on the share. If it runs as a user, then that user would need access.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...