All Apps and Add-ons

Imported logs not showing

appmandan
Path Finder

I have set up an FTP server on my splunk indexer so that our AS400 and FTP over log files. I have set up under "Files & Directories" in Splunk Manager a rule to continuously collect from the the same folder as the AS400 is FTPing the log file in. I'm not getting the log messages into Splunk or Splunk for AS/400. I have set the sourcetype to iseries and also tried dspjrn:5 and have verified the destination index is iseries. I'm still not able to pull in the logs. Does the log file itself need a specific name? The filename I'm trying to pull in is jern.jern. Any ideas?

Thanks

0 Karma
1 Solution

appmandan
Path Finder

This was a formatting error on the AS/400 logs before they were sent over

View solution in original post

appmandan
Path Finder

This was a formatting error on the AS/400 logs before they were sent over

appmandan
Path Finder

I went to Splunk Manager from the AS/400 app.

0 Karma

gnovak
Builder

Did you put the inputs into the correct app? What app were you in when you went to Manager and added the inputs?

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...