<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Monitor logs on a Unix Server from Windows Machine in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-logs-on-a-Unix-Server-from-Windows-Machine/m-p/33174#M5920</link>
    <description>&lt;P&gt;I installed Splunk on my Windows XP machine and I'm trying to setup the "Source" to "Monitor a file or directory" which is on a Unix box.  How do I accomplish this or does Splunk have to be installed on the Unix box?  When trying to put the full path I get an error that says "Encountered the following error while trying to save: In handler 'monitor': Path must be absolute"&lt;/P&gt;</description>
    <pubDate>Thu, 19 Aug 2010 02:47:15 GMT</pubDate>
    <dc:creator>jerry_john</dc:creator>
    <dc:date>2010-08-19T02:47:15Z</dc:date>
    <item>
      <title>Monitor logs on a Unix Server from Windows Machine</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-logs-on-a-Unix-Server-from-Windows-Machine/m-p/33174#M5920</link>
      <description>&lt;P&gt;I installed Splunk on my Windows XP machine and I'm trying to setup the "Source" to "Monitor a file or directory" which is on a Unix box.  How do I accomplish this or does Splunk have to be installed on the Unix box?  When trying to put the full path I get an error that says "Encountered the following error while trying to save: In handler 'monitor': Path must be absolute"&lt;/P&gt;</description>
      <pubDate>Thu, 19 Aug 2010 02:47:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-logs-on-a-Unix-Server-from-Windows-Machine/m-p/33174#M5920</guid>
      <dc:creator>jerry_john</dc:creator>
      <dc:date>2010-08-19T02:47:15Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor logs on a Unix Server from Windows Machine</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-logs-on-a-Unix-Server-from-Windows-Machine/m-p/33175#M5921</link>
      <description>&lt;P&gt;Installing Splunk on the Unix box is probably the best bet.  I believe you would be able to use syslog to forward various events in some method, but it would probably be less work just to set up the Unix box as a Splunk forwarder.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Aug 2010 02:49:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-logs-on-a-Unix-Server-from-Windows-Machine/m-p/33175#M5921</guid>
      <dc:creator>muebel</dc:creator>
      <dc:date>2010-08-19T02:49:59Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor logs on a Unix Server from Windows Machine</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-logs-on-a-Unix-Server-from-Windows-Machine/m-p/33176#M5922</link>
      <description>&lt;P&gt;There are quite a few ways to do this.&lt;/P&gt;

&lt;P&gt;Installing a Splunk Light Forwarder on the Unix box is the cleanest answer in many respects.&lt;/P&gt;

&lt;P&gt;Another option would be configure syslogd on the unix machine to forward events to a remote server, and then either install a syslog daemon such as Kiwi Syslog or have Splunk listen on the syslog port. If Splunk listens directly, you will lose events that occur while Splunk is not running.&lt;/P&gt;

&lt;P&gt;This isn't good for things like web server logs that are written directly to files, but works well for data sent via syslog.&lt;/P&gt;

&lt;P&gt;A third approach is to retrieve the files locally via ftp (or preferably SSH-based file copy), to a path that Splunk is indexing. If using scp/sftp, then you can generate a private key to allow authentication without a password. You can schedule the retrieval either as a separate Windows Task Scheduler job, or set up a scripted input in Splunk.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Sep 2010 04:16:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-logs-on-a-Unix-Server-from-Windows-Machine/m-p/33176#M5922</guid>
      <dc:creator>southeringtonp</dc:creator>
      <dc:date>2010-09-02T04:16:04Z</dc:date>
    </item>
  </channel>
</rss>

