<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What are some options for Forwarding OS logs from  a Full Splunk Ent instance? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/What-are-some-options-for-Forwarding-OS-logs-from-a-Full-Splunk/m-p/609243#M13614</link>
    <description>&lt;P&gt;Thank you for responding.&amp;nbsp; The release notes of the TA says it needs to be put on a forwarder.&amp;nbsp; But DS is a full Splunk Ent install.&amp;nbsp; Should we still install in the DS then ?&amp;nbsp; Alternatively, would configuring the local inputs.conf of the /opt/splunk/etc/system/local directory on DS by adding monitor stanzas also work ?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="neerajs_81_0-1660280598345.png" style="width: 651px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/21008i87C47C64FA344CF6/image-dimensions/651x254?v=v2" width="651" height="254" role="button" title="neerajs_81_0-1660280598345.png" alt="neerajs_81_0-1660280598345.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 12 Aug 2022 05:16:46 GMT</pubDate>
    <dc:creator>neerajs_81</dc:creator>
    <dc:date>2022-08-12T05:16:46Z</dc:date>
    <item>
      <title>What are some options for Forwarding OS logs from  a Full Splunk Ent instance?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-are-some-options-for-Forwarding-OS-logs-from-a-Full-Splunk/m-p/609185#M13607</link>
      <description>&lt;P&gt;Hi All,&amp;nbsp; &amp;nbsp;Splunk 101 question .&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;What are our options if we want to forward OS level logs ( For example: ssh user login/logout activity)&amp;nbsp; from a Deployment Server to our indexer.&amp;nbsp; &amp;nbsp;As a DS is a full Splunk Enterprise instance, it is not recommended to put UF on the same host.&amp;nbsp; &amp;nbsp; Where do i need to configure to tell it to monitor the OS syslog file also ? Is it /etc/system/local/inputs.conf&amp;nbsp; ?&amp;nbsp; If yes, how to maintain this inputs.conf copy for&amp;nbsp; updates&amp;nbsp; as i assume we cannot push updates to this file from the same host itself .&amp;nbsp; Any best practices here ?&lt;BR /&gt;&lt;BR /&gt;My DS is currently sending _audit, _introspection logs to the Idx ; which contain info about Splunk platform and not OS.&lt;BR /&gt;Hope i am clear.&amp;nbsp; &amp;nbsp;Thank you&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Aug 2022 14:48:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-are-some-options-for-Forwarding-OS-logs-from-a-Full-Splunk/m-p/609185#M13607</guid>
      <dc:creator>neerajs_81</dc:creator>
      <dc:date>2022-08-11T14:48:47Z</dc:date>
    </item>
    <item>
      <title>Re: What are some options for Forwarding OS logs from  a Full Splunk Ent instance?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-are-some-options-for-Forwarding-OS-logs-from-a-Full-Splunk/m-p/609217#M13611</link>
      <description>&lt;P&gt;It sounds like what you want is the Splunk Add-on for Unix and Linux:&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/833/" target="_blank"&gt;https://splunkbase.splunk.com/app/833/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The technical add-on (TA) will need to be installed on the DS and configured with your custom inputs.conf for the TA.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Aug 2022 20:26:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-are-some-options-for-Forwarding-OS-logs-from-a-Full-Splunk/m-p/609217#M13611</guid>
      <dc:creator>m_pham</dc:creator>
      <dc:date>2022-08-11T20:26:36Z</dc:date>
    </item>
    <item>
      <title>Re: What are some options for Forwarding OS logs from  a Full Splunk Ent instance?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-are-some-options-for-Forwarding-OS-logs-from-a-Full-Splunk/m-p/609243#M13614</link>
      <description>&lt;P&gt;Thank you for responding.&amp;nbsp; The release notes of the TA says it needs to be put on a forwarder.&amp;nbsp; But DS is a full Splunk Ent install.&amp;nbsp; Should we still install in the DS then ?&amp;nbsp; Alternatively, would configuring the local inputs.conf of the /opt/splunk/etc/system/local directory on DS by adding monitor stanzas also work ?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="neerajs_81_0-1660280598345.png" style="width: 651px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/21008i87C47C64FA344CF6/image-dimensions/651x254?v=v2" width="651" height="254" role="button" title="neerajs_81_0-1660280598345.png" alt="neerajs_81_0-1660280598345.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 05:16:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-are-some-options-for-Forwarding-OS-logs-from-a-Full-Splunk/m-p/609243#M13614</guid>
      <dc:creator>neerajs_81</dc:creator>
      <dc:date>2022-08-12T05:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: What are some options for Forwarding OS logs from  a Full Splunk Ent instance?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-are-some-options-for-Forwarding-OS-logs-from-a-Full-Splunk/m-p/609342#M13627</link>
      <description>&lt;P&gt;Splunk Enterprise server can forward data:&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.0/Forwarding/Aboutforwardingandreceivingdata#:~:text=You%20can%20forward%20data%20from,forwarding%20is%20called%20a%20forwarder.&amp;amp;text=A%20Splunk%20instance%20that%20receives,forwarders%20is%20called%20a%20receiver" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.0/Forwarding/Aboutforwardingandreceivingdata#:~:text=You%20can%20forward%20data%20from,forwarding%20is%20called%20a%20forwarder.&amp;amp;text=A%20Splunk%20instance%20that%20receives,forwarders%20is%20called%20a%20receiver&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best practice is for your custom inputs is in a separate addon - example: &lt;FONT face="courier new,courier"&gt;/opt/splunk/etc/apps/my_custom_app/local/inputs.conf&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;You should watch this to learn the basics of Splunk Administration:&amp;nbsp;&lt;A href="https://www.youtube.com/watch?v=O_w7rSWlHJs" target="_blank"&gt;https://www.youtube.com/watch?v=O_w7rSWlHJs&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 16:08:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-are-some-options-for-Forwarding-OS-logs-from-a-Full-Splunk/m-p/609342#M13627</guid>
      <dc:creator>m_pham</dc:creator>
      <dc:date>2022-08-12T16:08:59Z</dc:date>
    </item>
  </channel>
</rss>

