Getting Data In

How to configure path to log files present in remote servers?

vittalkumar
New Member

Hi All,

I recently installed splunk to analyze the logs.
These logs were recorded in remote server.
I want configure the path to these log files present in log servers.

Can anyone help me on this issue.

Thanks
Vittal Kumar

Tags (1)
0 Karma

kristian_kolb
Ultra Champion

You should probably install a Splunk Universal Forwarder (i.e. an agent) on the remote host, and configure it to send its data to the Splunk indexer.

http://docs.splunk.com/Documentation/Splunk/6.1.2/Forwarding/Aboutforwardingandreceivingdata

Then you need to configure the Forwarder to monitor the files you want to index in Splunk.

http://docs.splunk.com/Documentation/Splunk/6.1.2/Data/WhatSplunkcanmonitor

http://docs.splunk.com/Documentation/Splunk/6.1.2/Data/FilesDirsremote

The Splunk Universal Forwarder can be downloaded from the Download section at splunk.com. It does not cost anything.

http://www.splunk.com/download/universalforwarder

Hope this helps,

/K

Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...