<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configuring Apache log data forwarding in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Configuring-Apache-log-data-forwarding/m-p/26542#M4387</link>
    <description>&lt;P&gt;for the monitor, can I specify a wildcard in the access_log path (like /path/to/*.log, or does a separate [monitor] line need to be specified for each access_log?&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 09:40:09 GMT</pubDate>
    <dc:creator>compsavvystu</dc:creator>
    <dc:date>2020-09-28T09:40:09Z</dc:date>
    <item>
      <title>Configuring Apache log data forwarding</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configuring-Apache-log-data-forwarding/m-p/26540#M4385</link>
      <description>&lt;P&gt;I have a linux web server (Ubuntu 10.04 x64) that I would like to forward apache log data from. I have installed the universal forwarder. How do I configure it to forward log data to my splunk server?&lt;/P&gt;

&lt;P&gt;If this is well documented, I apologize. I'm having difficulty finding this info.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2011 16:14:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configuring-Apache-log-data-forwarding/m-p/26540#M4385</guid>
      <dc:creator>compsavvystu</dc:creator>
      <dc:date>2011-06-10T16:14:35Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Apache log data forwarding</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configuring-Apache-log-data-forwarding/m-p/26541#M4386</link>
      <description>&lt;P&gt;Minimally, in /opt/splunkforwarder/etc/system/local&lt;/P&gt;

&lt;P&gt;outputs.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout:somelabel]
server=192.168.0.1:9997
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;inputs.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///path/yo/your/access_log]
sourcetype = access_log
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;On the receiving end, you'll need to activate a corresponding receiving port under Management -&amp;gt; Forwrding/Receiving. (In this case, and by default, 9997.)&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2011 16:26:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configuring-Apache-log-data-forwarding/m-p/26541#M4386</guid>
      <dc:creator>twinspop</dc:creator>
      <dc:date>2011-06-10T16:26:37Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Apache log data forwarding</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configuring-Apache-log-data-forwarding/m-p/26542#M4387</link>
      <description>&lt;P&gt;for the monitor, can I specify a wildcard in the access_log path (like /path/to/*.log, or does a separate [monitor] line need to be specified for each access_log?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:40:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configuring-Apache-log-data-forwarding/m-p/26542#M4387</guid>
      <dc:creator>compsavvystu</dc:creator>
      <dc:date>2020-09-28T09:40:09Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Apache log data forwarding</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configuring-Apache-log-data-forwarding/m-p/26543#M4388</link>
      <description>&lt;P&gt;You can use a wild card, and that's better than a separate monitor stanza for each file.  If you need something more sophisticated, you can add either a whitelist or a blacklist to the spec.&lt;/P&gt;

&lt;P&gt;There is a new manual called "Getting Data In."  Start here (&lt;A href="http://www.splunk.com/base/Documentation/latest/Data/Configureyourinputs#Edit_inputs.conf"&gt;http://www.splunk.com/base/Documentation/latest/Data/Configureyourinputs#Edit_inputs.conf&lt;/A&gt;) in the manual for help with inputs.conf&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2011 22:52:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configuring-Apache-log-data-forwarding/m-p/26543#M4388</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2011-06-10T22:52:42Z</dc:date>
    </item>
  </channel>
</rss>

