<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to get data from Remote Server? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76477#M15606</link>
    <description>&lt;P&gt;OK. Where? What part of the setup are you struggling with?&lt;/P&gt;</description>
    <pubDate>Mon, 01 Oct 2012 14:04:23 GMT</pubDate>
    <dc:creator>Ayn</dc:creator>
    <dc:date>2012-10-01T14:04:23Z</dc:date>
    <item>
      <title>How to get data from Remote Server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76472#M15601</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;I am new to Splunk.&lt;/P&gt;

&lt;P&gt;We have central server where different types of logs are generated.&lt;/P&gt;

&lt;P&gt;How can I register or give reference of that Remote Server's URL in Splunk? &lt;BR /&gt;
(i.e. &lt;HOST ip=""&gt;:&lt;PORT&gt;/server/logs/)&lt;/PORT&gt;&lt;/HOST&gt;&lt;/P&gt;

&lt;P&gt;I want to register server url in Splunk so each time it fetches the updated indexed log details.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Oct 2012 13:49:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76472#M15601</guid>
      <dc:creator>pratiksurti</dc:creator>
      <dc:date>2012-10-01T13:49:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data from Remote Server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76473#M15602</link>
      <description>&lt;P&gt;You'll need to post more details on the remote server. How are the logs on it accessed? Through CIFS, HTTP, FTP, ...&lt;/P&gt;</description>
      <pubDate>Mon, 01 Oct 2012 13:57:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76473#M15602</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-10-01T13:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data from Remote Server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76474#M15603</link>
      <description>&lt;P&gt;You'll need a forwarder installed on that server so that the logs can get sent to Splunk to be indexed and searched centrally.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/Usingforwardingagents"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Data/Usingforwardingagents&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Oct 2012 14:00:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76474#M15603</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-10-01T14:00:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data from Remote Server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76475#M15604</link>
      <description>&lt;P&gt;Right now if we want to check logs, we do ssh from linux terminal or through FTP.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Oct 2012 14:01:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76475#M15604</guid>
      <dc:creator>pratiksurti</dc:creator>
      <dc:date>2012-10-01T14:01:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data from Remote Server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76476#M15605</link>
      <description>&lt;P&gt;I have installed forwarder.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Oct 2012 14:03:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76476#M15605</guid>
      <dc:creator>pratiksurti</dc:creator>
      <dc:date>2012-10-01T14:03:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data from Remote Server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76477#M15606</link>
      <description>&lt;P&gt;OK. Where? What part of the setup are you struggling with?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Oct 2012 14:04:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76477#M15606</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-10-01T14:04:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data from Remote Server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76478#M15607</link>
      <description>&lt;P&gt;while installing it ask for host detail two times with default port numbers, just to know where I can give my server details.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Oct 2012 14:06:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76478#M15607</guid>
      <dc:creator>pratiksurti</dc:creator>
      <dc:date>2012-10-01T14:06:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data from Remote Server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76479#M15608</link>
      <description>&lt;P&gt;Are you set up for forwarding and receiving according to the docs?  &lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Enableareceiver"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Enableareceiver&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Configureforwarderswithoutputs.confd"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Configureforwarderswithoutputs.confd&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Oct 2012 14:07:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76479#M15608</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-10-01T14:07:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data from Remote Server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76480#M15609</link>
      <description>&lt;P&gt;I have look into configuration files. Also I need to refer above links to check with my setup.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Oct 2012 14:14:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76480#M15609</guid>
      <dc:creator>pratiksurti</dc:creator>
      <dc:date>2012-10-01T14:14:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data from Remote Server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76481#M15610</link>
      <description>&lt;P&gt;Please post your configuration file settings for forwarding and receiving and maybe that will let us help you on this issue.   &lt;/P&gt;

&lt;P&gt;Look in &lt;SPLUNK_HOME&gt;/etc/system/local/inputs.conf&lt;/SPLUNK_HOME&gt;&lt;/P&gt;

&lt;P&gt;On the forwarder look in &lt;SPLUNK_HOME&gt;/etc/system/local/outputs.conf&lt;/SPLUNK_HOME&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Oct 2012 14:19:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76481#M15610</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-10-01T14:19:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data from Remote Server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76482#M15611</link>
      <description>&lt;P&gt;Just checking configuration and installation, After installing the forwarder on my machine, I can see, before only Splunk folder was there and now another folder SplunkForwarder is created. So there are two setup folders now, is this expected? Or I am missing something?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Oct 2012 14:28:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76482#M15611</guid>
      <dc:creator>pratiksurti</dc:creator>
      <dc:date>2012-10-01T14:28:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data from Remote Server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76483#M15612</link>
      <description>&lt;H2&gt;inputs.conf:&lt;/H2&gt;

&lt;P&gt;[default]&lt;BR /&gt;
host = localhost (My Workstation)&lt;/P&gt;

&lt;P&gt;[script://$SPLUNK_HOME\bin\scripts\splunk-admon.path]&lt;BR /&gt;
disabled = 0&lt;/P&gt;

&lt;P&gt;[script://$SPLUNK_HOME\bin\scripts\splunk-perfmon.path]&lt;BR /&gt;
disabled = 0&lt;/P&gt;

&lt;H2&gt;outputs.conf:&lt;/H2&gt;

&lt;P&gt;[tcpout]&lt;BR /&gt;
defaultGroup = &lt;EM&gt;.&lt;/EM&gt;.&lt;EM&gt;.&lt;/EM&gt;_9997&lt;/P&gt;

&lt;P&gt;[tcpout:&lt;EM&gt;.&lt;/EM&gt;.&lt;EM&gt;.&lt;/EM&gt;_9997]&lt;BR /&gt;
server = &lt;EM&gt;.&lt;/EM&gt;.&lt;EM&gt;.&lt;/EM&gt;:9997&lt;/P&gt;

&lt;P&gt;[tcpout-server://&lt;EM&gt;.&lt;/EM&gt;.&lt;EM&gt;.&lt;/EM&gt;:9997]&lt;/P&gt;</description>
      <pubDate>Mon, 01 Oct 2012 14:35:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76483#M15612</guid>
      <dc:creator>pratiksurti</dc:creator>
      <dc:date>2012-10-01T14:35:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data from Remote Server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76484#M15613</link>
      <description>&lt;P&gt;Go in the UI to Manager -&amp;gt; Forwarding and receiving and make sure you've got an entry there.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Enableareceiver#Set_up_receiving"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Enableareceiver#Set_up_receiving&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Oct 2012 14:56:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76484#M15613</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-10-01T14:56:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data from Remote Server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76485#M15614</link>
      <description>&lt;P&gt;I can see the entries. Now How can I make it work?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Oct 2012 15:04:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76485#M15614</guid>
      <dc:creator>pratiksurti</dc:creator>
      <dc:date>2012-10-01T15:04:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data from Remote Server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76486#M15615</link>
      <description>&lt;P&gt;I don't know about your outputs.conf settings.  I would try something standard like you see in the outputs.conf example in our docs.  This will send to server IP 10.10.1.155 on port 9997 which you have set up to recieve.&lt;/P&gt;

&lt;P&gt;[tcpout:groupname]&lt;BR /&gt;
server=10.10.1.155:9997&lt;/P&gt;

&lt;P&gt;You can look here $SPLUNK_HOME/var/log/splunk for the splunkd log to see issues as well that might help.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Oct 2012 15:35:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76486#M15615</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-10-01T15:35:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data from Remote Server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76487#M15616</link>
      <description>&lt;P&gt;I will work on it once I go back.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Oct 2012 17:53:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76487#M15616</guid>
      <dc:creator>pratiksurti</dc:creator>
      <dc:date>2012-10-01T17:53:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data from Remote Server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76488#M15617</link>
      <description>&lt;P&gt;If you don't want to use a forwarder you can use a scripted input to reterive the logs via ssh. If you don't want to read the entire log you might have to use a little logic, tail, grep to only read new lines.  The easiest way is to use the UF on your remote servers.&lt;/P&gt;

&lt;P&gt;inputs.conf&lt;BR /&gt;
&lt;CODE&gt;&lt;/CODE&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;BR /&gt;
#*nix&lt;BR /&gt;
[script://./bin/sshscript.sh ./bin/catfiles.sh]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
index = main&lt;BR /&gt;
sourcetype = somelogtype&lt;BR /&gt;
interval = 0 0 * * *&lt;BR /&gt;
&lt;/CODE&gt;&lt;/PRE&gt;&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;BR /&gt;
#sshscript.sh&lt;BR /&gt;
#&lt;EM&gt;nix&lt;BR /&gt;
#!/bin/bash&lt;BR /&gt;
ssh root\@remoteServer 'bash -s' &amp;lt; $1&lt;BR /&gt;
done&lt;BR /&gt;
&lt;/EM&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;
&lt;CODE&gt;&lt;/CODE&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;BR /&gt;
#catfiles.sh&lt;BR /&gt;
#*nix&lt;BR /&gt;
#!/bin/bash&lt;BR /&gt;
for file in /var/log/; do fcontent=\$(cat $file) printf '\%s' "\${file}\n"${fcont}";done&lt;BR /&gt;
&lt;/CODE&gt;&lt;/PRE&gt;&lt;/P&gt;

&lt;P&gt;For more info check my other post:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/59951/edit/" target="_blank"&gt;Can you set certain time forwarding occurs&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:32:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-data-from-Remote-Server/m-p/76488#M15617</guid>
      <dc:creator>bmacias84</dc:creator>
      <dc:date>2020-09-28T12:32:50Z</dc:date>
    </item>
  </channel>
</rss>

