<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there a feature in Splunk (similar to Dropbox) where can i drop multiple log files from multiple locations? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-feature-in-Splunk-similar-to-Dropbox-where-can-i-drop/m-p/252645#M48594</link>
    <description>&lt;P&gt;yes i know that. we need this kind of dropbox feature to store sample log files in lower environment which is used to play with the data   to create some dashboards and others. &lt;/P&gt;</description>
    <pubDate>Wed, 25 Jan 2017 01:58:01 GMT</pubDate>
    <dc:creator>sai_john</dc:creator>
    <dc:date>2017-01-25T01:58:01Z</dc:date>
    <item>
      <title>Is there a feature in Splunk (similar to Dropbox) where can i drop multiple log files from multiple locations?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-feature-in-Splunk-similar-to-Dropbox-where-can-i-drop/m-p/252642#M48591</link>
      <description>&lt;P&gt;Is there a feature in Splunk (like Dropbox) to drop all types of logs from different applications ?&lt;/P&gt;

&lt;P&gt;Where can i drop in multiple log files with multiple log types (.csv/.txt/.log) from multiple locations?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2017 23:14:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-feature-in-Splunk-similar-to-Dropbox-where-can-i-drop/m-p/252642#M48591</guid>
      <dc:creator>sai_john</dc:creator>
      <dc:date>2017-01-24T23:14:31Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a feature in Splunk (similar to Dropbox) where can i drop multiple log files from multiple locations?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-feature-in-Splunk-similar-to-Dropbox-where-can-i-drop/m-p/252643#M48592</link>
      <description>&lt;P&gt;Splunk really doesn't care where you put them.  You just tell the indexer what directories to watch, and it does the rest.&lt;/P&gt;

&lt;P&gt;You can look up details regarding forwarders (that move the data from place to place) and fishbuckets (part of how splunk tracks what it's done already), but really  you should just start here -&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.1/Data/Getstartedwithgettingdatain"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.1/Data/Getstartedwithgettingdatain&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.1/Data/Howdoyouwanttoadddata"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.1/Data/Howdoyouwanttoadddata&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 00:09:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-feature-in-Splunk-similar-to-Dropbox-where-can-i-drop/m-p/252643#M48592</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-01-25T00:09:13Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a feature in Splunk (similar to Dropbox) where can i drop multiple log files from multiple locations?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-feature-in-Splunk-similar-to-Dropbox-where-can-i-drop/m-p/252644#M48593</link>
      <description>&lt;P&gt;Just be sure you understand that Splunk is not a storage engine.  It's a machine data analytics platform.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 01:41:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-feature-in-Splunk-similar-to-Dropbox-where-can-i-drop/m-p/252644#M48593</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2017-01-25T01:41:23Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a feature in Splunk (similar to Dropbox) where can i drop multiple log files from multiple locations?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-feature-in-Splunk-similar-to-Dropbox-where-can-i-drop/m-p/252645#M48594</link>
      <description>&lt;P&gt;yes i know that. we need this kind of dropbox feature to store sample log files in lower environment which is used to play with the data   to create some dashboards and others. &lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 01:58:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-feature-in-Splunk-similar-to-Dropbox-where-can-i-drop/m-p/252645#M48594</guid>
      <dc:creator>sai_john</dc:creator>
      <dc:date>2017-01-25T01:58:01Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a feature in Splunk (similar to Dropbox) where can i drop multiple log files from multiple locations?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-feature-in-Splunk-similar-to-Dropbox-where-can-i-drop/m-p/252646#M48595</link>
      <description>&lt;P&gt;So let's peel that onion...  Are all *.log files going to have the same data formats?&lt;/P&gt;

&lt;P&gt;If so you can easily monitor one directory like this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///var/dropfolder/*.log]
sourcetype=myLogs
index=myIndex
crcSalt=&amp;lt;SOURCE&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;However, if each .log file has different formats, then you'll need to be more specific like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///var/dropfolder/app1*.log]
sourcetype=myApp1Log
index=myIndex
crcSalt=&amp;lt;SOURCE&amp;gt;

[monitor:///var/dropfolder/otherApp*.log]
sourcetype=myOtherAppLog
index=myIndex
crcSalt=&amp;lt;SOURCE&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;You need to do this because later you'll want to perform field extractions on each log type, and the regex or other methods to extract those fields will be different for each data format you have.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 02:13:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-feature-in-Splunk-similar-to-Dropbox-where-can-i-drop/m-p/252646#M48595</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2017-01-25T02:13:19Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a feature in Splunk (similar to Dropbox) where can i drop multiple log files from multiple locations?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-feature-in-Splunk-similar-to-Dropbox-where-can-i-drop/m-p/252647#M48596</link>
      <description>&lt;P&gt;yeah this is the regular process to add data from different data formats.&lt;BR /&gt;
But i am not looking to get data from different servers/data format  since i just want to place my sample log files(.csv / .txt) to play with that sample data.  Does Splunk provides an appor some other feature to place/drop sample multiple log files and then play around that by extracting fields?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 03:10:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-feature-in-Splunk-similar-to-Dropbox-where-can-i-drop/m-p/252647#M48596</guid>
      <dc:creator>sai_john</dc:creator>
      <dc:date>2017-01-25T03:10:17Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a feature in Splunk (similar to Dropbox) where can i drop multiple log files from multiple locations?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-feature-in-Splunk-similar-to-Dropbox-where-can-i-drop/m-p/252648#M48597</link>
      <description>&lt;P&gt;You would create a wild carded monitor stanza&lt;/P&gt;

&lt;P&gt;[monitor:///var/dropfolder/*]&lt;/P&gt;

&lt;P&gt;If you don't specify a sourcetype, Splunk will attempt to detect one for you. It should be fine for csv, JSON, IIS logs, Apache logs, and a hand full of other known log types.&lt;/P&gt;

&lt;P&gt;But I'm telling it's going to get ugly...&lt;/P&gt;

&lt;P&gt;There is no app for this because everyone's data is different and people would constantly complain about the app.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 03:21:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-feature-in-Splunk-similar-to-Dropbox-where-can-i-drop/m-p/252648#M48597</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2017-01-25T03:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a feature in Splunk (similar to Dropbox) where can i drop multiple log files from multiple locations?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-feature-in-Splunk-similar-to-Dropbox-where-can-i-drop/m-p/252649#M48598</link>
      <description>&lt;P&gt;yeah i understood that. you are talking about adding new data from different servers/data formats. you are correct in that perspective. But i am talking about sample files which are in my local desktop.&lt;/P&gt;

&lt;P&gt;For example I have exported 10 sample log files(lets talk about only csv files) from splunk from 10 sourcetypes into my local desktop.&lt;/P&gt;

&lt;P&gt;Now  i want to place/drop these 10 .csv sample files into __&lt;STRONG&gt;&lt;EM&gt;(kind of dropbox /some app)&lt;/EM&gt;&lt;/STRONG&gt;__ to search from that sample data which is present in those 10 csv files.                           &lt;/P&gt;

&lt;P&gt;i want to know if there is an app/feature in splunk similar to dropbox to place these 10 csv files and then  tweek.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 03:57:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-feature-in-Splunk-similar-to-Dropbox-where-can-i-drop/m-p/252649#M48598</guid>
      <dc:creator>sai_john</dc:creator>
      <dc:date>2017-01-25T03:57:58Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a feature in Splunk (similar to Dropbox) where can i drop multiple log files from multiple locations?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-feature-in-Splunk-similar-to-Dropbox-where-can-i-drop/m-p/252650#M48599</link>
      <description>&lt;P&gt;Hi sai_John,&lt;BR /&gt;
The only way to drop a file after indexing is to schedule a script that deletes files older than a time.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe &lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 06:36:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-feature-in-Splunk-similar-to-Dropbox-where-can-i-drop/m-p/252650#M48599</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-01-25T06:36:23Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a feature in Splunk (similar to Dropbox) where can i drop multiple log files from multiple locations?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-feature-in-Splunk-similar-to-Dropbox-where-can-i-drop/m-p/252651#M48600</link>
      <description>&lt;P&gt;Hi sai_John,&lt;BR /&gt;
The only way to drop a file after indexing is to schedule a script that deletes files older than a time.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe &lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 06:36:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-feature-in-Splunk-similar-to-Dropbox-where-can-i-drop/m-p/252651#M48600</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-01-25T06:36:23Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a feature in Splunk (similar to Dropbox) where can i drop multiple log files from multiple locations?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-feature-in-Splunk-similar-to-Dropbox-where-can-i-drop/m-p/252652#M48601</link>
      <description>&lt;P&gt;Yes, you do what I've said.&lt;/P&gt;

&lt;P&gt;Create an input that is monitoring a folder on your machine for *, then you drop the files in that folder.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 15:48:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-feature-in-Splunk-similar-to-Dropbox-where-can-i-drop/m-p/252652#M48601</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2017-01-25T15:48:37Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a feature in Splunk (similar to Dropbox) where can i drop multiple log files from multiple locations?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-feature-in-Splunk-similar-to-Dropbox-where-can-i-drop/m-p/252653#M48602</link>
      <description>&lt;P&gt;If you're talking about editing the files in the folder, then no.  Splunk is not a UI for editing data like Google docs.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 15:50:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-feature-in-Splunk-similar-to-Dropbox-where-can-i-drop/m-p/252653#M48602</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2017-01-25T15:50:46Z</dc:date>
    </item>
  </channel>
</rss>

