<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to confgure splunk to monitor apache web server in Security</title>
    <link>https://community.splunk.com/t5/Security/how-to-confgure-splunk-to-monitor-apache-web-server/m-p/152342#M4631</link>
    <description>&lt;P&gt;Thanks MuS&lt;BR /&gt;
           Thanks for your response. I have modified input.conf based on your answer.i have enabled listening port for 9997 .then ????i am really new to splunk ,,those links are really confusing me,,please direct me to the steps where i can accomplish this with only required few steps i apologize if i done anything wrong..&lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
    <pubDate>Wed, 17 Dec 2014 07:33:49 GMT</pubDate>
    <dc:creator>vahabudeen</dc:creator>
    <dc:date>2014-12-17T07:33:49Z</dc:date>
    <item>
      <title>how to confgure splunk to monitor apache web server</title>
      <link>https://community.splunk.com/t5/Security/how-to-confgure-splunk-to-monitor-apache-web-server/m-p/152340#M4629</link>
      <description>&lt;P&gt;Hi all&lt;BR /&gt;
      I have installed Splunk Enterprise trial on a windows 7 machine to collect logs from my Apache server ,also installed Splunk universal forwarder on my Apache server (centos 6).how do i configure These two to monitor my apache web server.&lt;/P&gt;

&lt;P&gt;Here is what i have done ...though it doesn't help&lt;BR /&gt;
outputs.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout:Apache]
server=ApacheserevrIP:9997
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;inputs.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:/var/log/httpd/access_log]
sourcetype = access_log
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Please direct me to the correct solution&lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2014 06:55:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/how-to-confgure-splunk-to-monitor-apache-web-server/m-p/152340#M4629</guid>
      <dc:creator>vahabudeen</dc:creator>
      <dc:date>2014-12-17T06:55:22Z</dc:date>
    </item>
    <item>
      <title>Re: how to confgure splunk to monitor apache web server</title>
      <link>https://community.splunk.com/t5/Security/how-to-confgure-splunk-to-monitor-apache-web-server/m-p/152341#M4630</link>
      <description>&lt;P&gt;Hi vahabudeen,&lt;/P&gt;

&lt;P&gt;first check that inputs.conf it should be like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///var/log/httpd/access_log]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;You missed some slashes there. Next, have you enabled receiving on your indexer? See docs &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.0/Forwarding/Enableareceiver"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.0/Forwarding/Enableareceiver&lt;/A&gt; and last but not least make sure the forwarder is able to reach / communicate with the indexer on that port (firewalls, routing ....)&lt;/P&gt;

&lt;P&gt;hope this helps ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2014 07:09:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/how-to-confgure-splunk-to-monitor-apache-web-server/m-p/152341#M4630</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-12-17T07:09:09Z</dc:date>
    </item>
    <item>
      <title>Re: how to confgure splunk to monitor apache web server</title>
      <link>https://community.splunk.com/t5/Security/how-to-confgure-splunk-to-monitor-apache-web-server/m-p/152342#M4631</link>
      <description>&lt;P&gt;Thanks MuS&lt;BR /&gt;
           Thanks for your response. I have modified input.conf based on your answer.i have enabled listening port for 9997 .then ????i am really new to splunk ,,those links are really confusing me,,please direct me to the steps where i can accomplish this with only required few steps i apologize if i done anything wrong..&lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2014 07:33:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/how-to-confgure-splunk-to-monitor-apache-web-server/m-p/152342#M4631</guid>
      <dc:creator>vahabudeen</dc:creator>
      <dc:date>2014-12-17T07:33:49Z</dc:date>
    </item>
    <item>
      <title>Re: how to confgure splunk to monitor apache web server</title>
      <link>https://community.splunk.com/t5/Security/how-to-confgure-splunk-to-monitor-apache-web-server/m-p/152343#M4632</link>
      <description>&lt;P&gt;Your step by step instruction is &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/WelcometotheSearchTutorial"&gt;http://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/WelcometotheSearchTutorial&lt;/A&gt; Part3 and Part4 are essential, especially to new users.&lt;/P&gt;

&lt;P&gt;But as small hint, search the &lt;CODE&gt;index=main&lt;/CODE&gt; or &lt;CODE&gt;sourcetype=access_logs&lt;/CODE&gt; on your indexer&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2014 07:39:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/how-to-confgure-splunk-to-monitor-apache-web-server/m-p/152343#M4632</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-12-17T07:39:45Z</dc:date>
    </item>
    <item>
      <title>Re: how to confgure splunk to monitor apache web server</title>
      <link>https://community.splunk.com/t5/Security/how-to-confgure-splunk-to-monitor-apache-web-server/m-p/152344#M4633</link>
      <description>&lt;P&gt;after configuration of universal forwarder to send logs to Splunk manager ,how can i verify whether it is received or not??&lt;BR /&gt;
then only i would be able to move with "add data" and dashboard steps ,,isn't it??&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2014 08:49:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/how-to-confgure-splunk-to-monitor-apache-web-server/m-p/152344#M4633</guid>
      <dc:creator>vahabudeen</dc:creator>
      <dc:date>2014-12-17T08:49:22Z</dc:date>
    </item>
    <item>
      <title>Re: how to confgure splunk to monitor apache web server</title>
      <link>https://community.splunk.com/t5/Security/how-to-confgure-splunk-to-monitor-apache-web-server/m-p/152345#M4634</link>
      <description>&lt;P&gt;on your indexer, check the &lt;CODE&gt;index=_internal&lt;/CODE&gt; and/or fire this command on your forwarder &lt;CODE&gt;$SPLUNK_HOME/bin/splunk list forward-server&lt;/CODE&gt; No need to &lt;CODE&gt;add data&lt;/CODE&gt; because you already receive your logs from the forwarder; this would only be needed if your really want to add something else.&lt;/P&gt;

&lt;P&gt;Open the search app and search for your events by running a basic first search like &lt;CODE&gt;index=* sourcetype=access_logs&lt;/CODE&gt; and run it over &lt;CODE&gt;all time&lt;/CODE&gt; to verify events are getting in. Next step would be to create a useful search and some fancy dashboard that fits your needs.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2014 08:59:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/how-to-confgure-splunk-to-monitor-apache-web-server/m-p/152345#M4634</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-12-17T08:59:57Z</dc:date>
    </item>
  </channel>
</rss>

