<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to add log data that is currently pulled from a shared folder? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-log-data-that-is-currently-pulled-from-a-shared/m-p/291421#M55554</link>
    <description>&lt;P&gt;You can certainly set up a forwarder to do this. You would install that forwarder where it can access those various directories you want to monitor, then take the inputs from the inputs.conf on your Splunk instance and put them on that forwarder. &lt;/P&gt;

&lt;P&gt;If you aren't forwarding the data to your standalone Splunk instances there is probably an inputs.conf  on the indexer bringing in the data. &lt;/P&gt;

&lt;P&gt;Regardless of where the inputs.conf is you will need the stanzas in that conf file that monitors the directories you want. You want those on the forwarder inputs.conf&lt;/P&gt;

&lt;P&gt;You can then get the forwarder to send data to Splunk Cloud. You will need to download the Splunk Cloud forwarder credentials app and install it on the forwarder. Here is the directions &lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/6.5.1612/User/ForwardDataToSplunkCloudFromWindows"&gt;https://docs.splunk.com/Documentation/SplunkCloud/6.5.1612/User/ForwardDataToSplunkCloudFromWindows&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 08 Feb 2017 19:22:46 GMT</pubDate>
    <dc:creator>kmccririe_splun</dc:creator>
    <dc:date>2017-02-08T19:22:46Z</dc:date>
    <item>
      <title>How to add log data that is currently pulled from a shared folder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-log-data-that-is-currently-pulled-from-a-shared/m-p/291418#M55551</link>
      <description>&lt;P&gt;I'm wondering with Splunk Cloud, how does one migrate log inputs that are watching a directory and grabbing new files as they come in? Obviously Splunk Cloud has no access to my systems anymore, so how does one go about migrating these type of jobs to Splunk Cloud?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2017 17:50:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-log-data-that-is-currently-pulled-from-a-shared/m-p/291418#M55551</guid>
      <dc:creator>tmblue</dc:creator>
      <dc:date>2017-02-08T17:50:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to add log data that is currently pulled from a shared folder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-log-data-that-is-currently-pulled-from-a-shared/m-p/291419#M55552</link>
      <description>&lt;P&gt;Where are you migrating from? Is this from on a prem installation to Splunk cloud? Are you using a forwarder?&lt;/P&gt;

&lt;P&gt;I am trying to figure out what inputs you are mentioning and where they are located.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2017 18:33:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-log-data-that-is-currently-pulled-from-a-shared/m-p/291419#M55552</guid>
      <dc:creator>kmccririe_splun</dc:creator>
      <dc:date>2017-02-08T18:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to add log data that is currently pulled from a shared folder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-log-data-that-is-currently-pulled-from-a-shared/m-p/291420#M55553</link>
      <description>&lt;P&gt;Thank you. i'm coming from a standalone installation at the moment. single indexer, search head etc.  It currently has multiple inputs that are "watching various directories on a shared NFS volume" We are looking to migrate to Splunk Cloud and I'm trying to understand how I do this migration.   Sounds like I need a forwarder to push to splunk cloud, but honestly I'm not 100% sure how I accomplish that from where I currently am (stand alone installation).&lt;/P&gt;

&lt;P&gt;Thanks again&lt;/P&gt;

&lt;P&gt;Tory&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2017 19:12:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-log-data-that-is-currently-pulled-from-a-shared/m-p/291420#M55553</guid>
      <dc:creator>tmblue</dc:creator>
      <dc:date>2017-02-08T19:12:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to add log data that is currently pulled from a shared folder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-log-data-that-is-currently-pulled-from-a-shared/m-p/291421#M55554</link>
      <description>&lt;P&gt;You can certainly set up a forwarder to do this. You would install that forwarder where it can access those various directories you want to monitor, then take the inputs from the inputs.conf on your Splunk instance and put them on that forwarder. &lt;/P&gt;

&lt;P&gt;If you aren't forwarding the data to your standalone Splunk instances there is probably an inputs.conf  on the indexer bringing in the data. &lt;/P&gt;

&lt;P&gt;Regardless of where the inputs.conf is you will need the stanzas in that conf file that monitors the directories you want. You want those on the forwarder inputs.conf&lt;/P&gt;

&lt;P&gt;You can then get the forwarder to send data to Splunk Cloud. You will need to download the Splunk Cloud forwarder credentials app and install it on the forwarder. Here is the directions &lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/6.5.1612/User/ForwardDataToSplunkCloudFromWindows"&gt;https://docs.splunk.com/Documentation/SplunkCloud/6.5.1612/User/ForwardDataToSplunkCloudFromWindows&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2017 19:22:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-log-data-that-is-currently-pulled-from-a-shared/m-p/291421#M55554</guid>
      <dc:creator>kmccririe_splun</dc:creator>
      <dc:date>2017-02-08T19:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to add log data that is currently pulled from a shared folder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-log-data-that-is-currently-pulled-from-a-shared/m-p/291422#M55555</link>
      <description>&lt;P&gt;@tmblue - Did the answer provided by kmccririe help provide a working solution to your question? If yes, please don't forget to resolve this post by clicking "Accept". If no, please leave a comment with more feedback. Thanks!&lt;/P&gt;</description>
      <pubDate>Sat, 11 Mar 2017 18:20:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-log-data-that-is-currently-pulled-from-a-shared/m-p/291422#M55555</guid>
      <dc:creator>aaraneta_splunk</dc:creator>
      <dc:date>2017-03-11T18:20:54Z</dc:date>
    </item>
  </channel>
</rss>

