Splunk Enterprise

How to ask Splunk to get/retrieve a log file?

splunkbee
New Member

Hi,

My log files are stored an a machine. There is no way I can tell this machine to send them somewhere. I must manually go into some directories and pull them all out.
Can Splunk do that for me?

Thanks

0 Karma

woodcock
Esteemed Legend

When you do a "pull" for data instead of a "push", you have to write some glue. You need a Universal Forwarder as a way-station and then you write a script to go to the source machine and pull the data to the UF. You then use traditional means to forward from there, being careful to use the original host for field host (instead of the UF's value).

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...