<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: extract log files on one Active Directory OU in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/extract-log-files-on-one-Active-Directory-OU/m-p/381968#M6343</link>
    <description>&lt;P&gt;Can you show where logs are stored? I meant "path\to\file".&lt;BR /&gt;
PS: Mask sensitive information(if any).&lt;/P&gt;</description>
    <pubDate>Wed, 01 Aug 2018 13:13:33 GMT</pubDate>
    <dc:creator>sudosplunk</dc:creator>
    <dc:date>2018-08-01T13:13:33Z</dc:date>
    <item>
      <title>extract log files on one Active Directory OU</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/extract-log-files-on-one-Active-Directory-OU/m-p/381965#M6340</link>
      <description>&lt;P&gt;Possible unique situation.  I work for a state agency and each state agency is under the same domain. So each state agency is its own OU in AD (I know its bad but it is the way it is).  We need to extract only log files  pertaining to my own agency. The group that manages AD wants to dump the logs on a share and for us to import. Is it possible to use a heavy forwarder to extract the log files for my agency only?  I'm not sure if it is possible.  I'm sorry if this is confusing. I'm not looking for a step by step just general info if possible.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Aug 2018 11:54:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/extract-log-files-on-one-Active-Directory-OU/m-p/381965#M6340</guid>
      <dc:creator>rapture005</dc:creator>
      <dc:date>2018-08-01T11:54:54Z</dc:date>
    </item>
    <item>
      <title>Re: extract log files on one Active Directory OU</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/extract-log-files-on-one-Active-Directory-OU/m-p/381966#M6341</link>
      <description>&lt;P&gt;Hello, &lt;/P&gt;

&lt;P&gt;While HF can do the job, you can use Universal Forwarder also to ingest logs from share. It would be easy if the log files have some kind of unique name which differentiates it with other log files. Please provide some examples with screenshots or samples to further assist you. &lt;/P&gt;

&lt;P&gt;Meanwhile, you can find good explanation with steps &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.1.2/Data/Monitorfilesanddirectorieswithinputs.conf"&gt;here&lt;/A&gt;. &lt;/P&gt;</description>
      <pubDate>Wed, 01 Aug 2018 12:28:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/extract-log-files-on-one-Active-Directory-OU/m-p/381966#M6341</guid>
      <dc:creator>sudosplunk</dc:creator>
      <dc:date>2018-08-01T12:28:55Z</dc:date>
    </item>
    <item>
      <title>Re: extract log files on one Active Directory OU</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/extract-log-files-on-one-Active-Directory-OU/m-p/381967#M6342</link>
      <description>&lt;P&gt;thanks for the quick response. That is what I'm afraid of how to differentiate the groups. I'm working on getting some data to test.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Aug 2018 13:08:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/extract-log-files-on-one-Active-Directory-OU/m-p/381967#M6342</guid>
      <dc:creator>rapture005</dc:creator>
      <dc:date>2018-08-01T13:08:30Z</dc:date>
    </item>
    <item>
      <title>Re: extract log files on one Active Directory OU</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/extract-log-files-on-one-Active-Directory-OU/m-p/381968#M6343</link>
      <description>&lt;P&gt;Can you show where logs are stored? I meant "path\to\file".&lt;BR /&gt;
PS: Mask sensitive information(if any).&lt;/P&gt;</description>
      <pubDate>Wed, 01 Aug 2018 13:13:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/extract-log-files-on-one-Active-Directory-OU/m-p/381968#M6343</guid>
      <dc:creator>sudosplunk</dc:creator>
      <dc:date>2018-08-01T13:13:33Z</dc:date>
    </item>
  </channel>
</rss>

