<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple server logs indexing in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Multiple-server-logs-indexing/m-p/86135#M17910</link>
    <description>&lt;P&gt;(spam removed)&lt;/P&gt;</description>
    <pubDate>Mon, 14 Jan 2013 07:10:56 GMT</pubDate>
    <dc:creator>pioneer817</dc:creator>
    <dc:date>2013-01-14T07:10:56Z</dc:date>
    <item>
      <title>Multiple server logs indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Multiple-server-logs-indexing/m-p/86133#M17908</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;We have our application in multiple servers, we need to index the log files.&lt;/P&gt;

&lt;P&gt;two options to do that.&lt;/P&gt;

&lt;P&gt;1)  Using forwarder/receiver   - do we need to install forwarder to all server or is there any way we can achieve this.&lt;BR /&gt;
2)  Using Shell script – coping the logs files to destination and indexing in SPLUNK.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2013 02:50:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Multiple-server-logs-indexing/m-p/86133#M17908</guid>
      <dc:creator>ganeshgs</dc:creator>
      <dc:date>2013-01-14T02:50:58Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple server logs indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Multiple-server-logs-indexing/m-p/86134#M17909</link>
      <description>&lt;P&gt;I would install the forwarder on all the servers. It will be easier than using a shell script, and work better.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2013 07:03:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Multiple-server-logs-indexing/m-p/86134#M17909</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2013-01-14T07:03:40Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple server logs indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Multiple-server-logs-indexing/m-p/86135#M17910</link>
      <description>&lt;P&gt;(spam removed)&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2013 07:10:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Multiple-server-logs-indexing/m-p/86135#M17910</guid>
      <dc:creator>pioneer817</dc:creator>
      <dc:date>2013-01-14T07:10:56Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple server logs indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Multiple-server-logs-indexing/m-p/86136#M17911</link>
      <description>&lt;P&gt;But we run application on 21 servers on Load Balancing. &lt;BR /&gt;
we are checking for any possibility in splunk to connect from receiver to other servers through SSH, like Putty.&lt;BR /&gt;
By this way we can directly point to individual server log files through  "Data Inputs &amp;gt;&amp;gt; files and directories" option and make splunk to listen to this logs and continuously collect data.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2013 07:33:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Multiple-server-logs-indexing/m-p/86136#M17911</guid>
      <dc:creator>ganeshgs</dc:creator>
      <dc:date>2013-01-14T07:33:32Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple server logs indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Multiple-server-logs-indexing/m-p/86137#M17912</link>
      <description>&lt;P&gt;I concur Lisa's suggestion. Using the forwarder will be useful when deploying in large enterprises. If you do not use scripted inputs, it will also allow business continuity. You can further use a deployment server, to manage it when you have too many forwarders to look at.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2013 07:54:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Multiple-server-logs-indexing/m-p/86137#M17912</guid>
      <dc:creator>e82than</dc:creator>
      <dc:date>2013-01-14T07:54:55Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple server logs indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Multiple-server-logs-indexing/m-p/86138#M17913</link>
      <description>&lt;P&gt;You can make the forwarders point to individual server log files as well. For a large number of forwarders you can use the deployment server to roll out any configuration changes to similar forwarders in one go.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2013 08:17:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Multiple-server-logs-indexing/m-p/86138#M17913</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2013-01-14T08:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple server logs indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Multiple-server-logs-indexing/m-p/86139#M17914</link>
      <description>&lt;P&gt;One quick clarification. I guess even deployment server  also suggest to install splunk instance in each servers.&lt;BR /&gt;
So what if we hosted our application in cloud environment and have limited access to servers.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2013 08:32:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Multiple-server-logs-indexing/m-p/86139#M17914</guid>
      <dc:creator>ganeshgs</dc:creator>
      <dc:date>2013-01-14T08:32:17Z</dc:date>
    </item>
  </channel>
</rss>

