<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Logs from specific application in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/Logs-from-specific-application/m-p/428380#M7662</link>
    <description>&lt;P&gt;I suppose this application does not come free of charge. Perhaps you could file a support ticket with Cerner and ask them directly how logging is done.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 14:48:25 GMT</pubDate>
    <dc:creator>whrg</dc:creator>
    <dc:date>2019-03-12T14:48:25Z</dc:date>
    <item>
      <title>Logs from specific application</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Logs-from-specific-application/m-p/428377#M7659</link>
      <description>&lt;P&gt;We have a application that can be used as a backup to our Electronic Medical Record.  Using Splunk Enterprise, I need to run a report that shows which users logged into this application from which workstation.  The application is logged in via LDAP credentials.  I would like the report to show hostname, username, login time, logout time.&lt;/P&gt;

&lt;P&gt;Unfortunately, I am not sure where to start.  Any help will be appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:59:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Logs-from-specific-application/m-p/428377#M7659</guid>
      <dc:creator>smithjl</dc:creator>
      <dc:date>2019-03-11T21:59:09Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from specific application</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Logs-from-specific-application/m-p/428378#M7660</link>
      <description>&lt;P&gt;Could you tell us which particular application you are using?&lt;/P&gt;

&lt;P&gt;Here is some general advice:&lt;/P&gt;

&lt;P&gt;First, you need to figure out if and how your application handles logging and then get these logs in Splunk.&lt;/P&gt;

&lt;P&gt;Check in the application's settings if you can configure log forwarding. Many applications can push their logs to a remote Syslog server. You could also check the application's manual if one exists.&lt;/P&gt;

&lt;P&gt;If you have access to the application's operating system then you could search for interesting log files in the file system. For example, under Linux, some applications log to /var/log or /opt/application/log. A Splunk Universal Forwarder (if supported by the operating system) could monitor these log files and send them to your Splunk Enterprise server.&lt;/P&gt;

&lt;P&gt;Also check splunkbase.com if any apps exist for this application.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 10:23:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Logs-from-specific-application/m-p/428378#M7660</guid>
      <dc:creator>whrg</dc:creator>
      <dc:date>2019-03-12T10:23:41Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from specific application</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Logs-from-specific-application/m-p/428379#M7661</link>
      <description>&lt;P&gt;Thank you for the advice, whrg.  The application is called 724 Access Viewer.  It is a Cerner application that aids our nursing staff in caring for patients during a system/network outage.  The application is installed on a Windows 10 PC which has the Universal Forwarder installed and reporting to our indexer.  In fact, I was trying to glean the information from these events, but I am having difficulty finding what we are looking for.  I will check on the logging from the application itself.  I searched splunkbase for Cerner, but I will go back and search for 724 specifically.,Thank you for the advice.  The application is called 724 Access Viewer.  It is a Cerner application which allows our nursing staff to provide care to patients in the event of a system/network outage.  The application is installed on a Windows 10 PC which has the Universal Forwarder installed and reporting to our indexer.  I will check on the logging from the application itself.  I checked splunkbase yesterday, but I was unable to find any apps for Cerner.  I will check again for 724 specifically.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:40:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Logs-from-specific-application/m-p/428379#M7661</guid>
      <dc:creator>smithjl</dc:creator>
      <dc:date>2019-03-12T13:40:54Z</dc:date>
    </item>
    <item>
      <title>Re: Logs from specific application</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Logs-from-specific-application/m-p/428380#M7662</link>
      <description>&lt;P&gt;I suppose this application does not come free of charge. Perhaps you could file a support ticket with Cerner and ask them directly how logging is done.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 14:48:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Logs-from-specific-application/m-p/428380#M7662</guid>
      <dc:creator>whrg</dc:creator>
      <dc:date>2019-03-12T14:48:25Z</dc:date>
    </item>
  </channel>
</rss>

