<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How does Splunk get logs from Linux or Windows servers? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-get-logs-from-Linux-or-Windows-servers/m-p/352278#M64571</link>
    <description>&lt;P&gt;I think you should read docs on how to Get Data into Splunk, here is a great starting point : &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.0/Data/WhatSplunkcanmonitor"&gt;http://docs.splunk.com/Documentation/Splunk/7.0.0/Data/WhatSplunkcanmonitor&lt;/A&gt; .&lt;/P&gt;

&lt;P&gt;In a nutshell, there is an agent (Universal Forwarder) that you deploy. On this agent, you tell it what to collect and where to send it. &lt;/P&gt;</description>
    <pubDate>Mon, 06 Nov 2017 07:03:18 GMT</pubDate>
    <dc:creator>esix_splunk</dc:creator>
    <dc:date>2017-11-06T07:03:18Z</dc:date>
    <item>
      <title>How does Splunk get logs from Linux or Windows servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-get-logs-from-Linux-or-Windows-servers/m-p/352277#M64570</link>
      <description>&lt;P&gt;i am a beginner&lt;/P&gt;

&lt;P&gt;how do splunk get log from linux server or window server?&lt;/P&gt;

&lt;P&gt;do (Active) splunk actively get log from linux server or window server    or (Passive) linux server or window server send log to splunk actively ?&lt;/P&gt;

&lt;P&gt;if splunk actively get log from linux server or window server , where can i configure this server list in splunk?&lt;BR /&gt;
if linux server or window server send log to splunk that get log passively, what is the command and format do i need to send this log&lt;/P&gt;

&lt;P&gt;can i send window server log with python script using udp to send to splunk like send to syslog of linux ?&lt;BR /&gt;
what is the ip address and port i need to send&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2017 02:48:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-get-logs-from-Linux-or-Windows-servers/m-p/352277#M64570</guid>
      <dc:creator>cyberportnoc</dc:creator>
      <dc:date>2017-11-06T02:48:02Z</dc:date>
    </item>
    <item>
      <title>Re: How does Splunk get logs from Linux or Windows servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-get-logs-from-Linux-or-Windows-servers/m-p/352278#M64571</link>
      <description>&lt;P&gt;I think you should read docs on how to Get Data into Splunk, here is a great starting point : &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.0/Data/WhatSplunkcanmonitor"&gt;http://docs.splunk.com/Documentation/Splunk/7.0.0/Data/WhatSplunkcanmonitor&lt;/A&gt; .&lt;/P&gt;

&lt;P&gt;In a nutshell, there is an agent (Universal Forwarder) that you deploy. On this agent, you tell it what to collect and where to send it. &lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2017 07:03:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-get-logs-from-Linux-or-Windows-servers/m-p/352278#M64571</guid>
      <dc:creator>esix_splunk</dc:creator>
      <dc:date>2017-11-06T07:03:18Z</dc:date>
    </item>
    <item>
      <title>Re: How does Splunk get logs from Linux or Windows servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-get-logs-from-Linux-or-Windows-servers/m-p/352279#M64572</link>
      <description>&lt;P&gt;i find previous peer's guideline, he use add data -&amp;gt; upload, it upload a zip file and then choose server&lt;BR /&gt;
but what is this zip file, what do it zip?&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2017 07:09:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-get-logs-from-Linux-or-Windows-servers/m-p/352279#M64572</guid>
      <dc:creator>cyberportnoc</dc:creator>
      <dc:date>2017-11-06T07:09:52Z</dc:date>
    </item>
    <item>
      <title>Re: How does Splunk get logs from Linux or Windows servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-get-logs-from-Linux-or-Windows-servers/m-p/352280#M64573</link>
      <description>&lt;P&gt;That would be a zip file from a server, and it contains log files. If you dont know what ZIP, or archive files are, you should spend sometime on your favorite search engine to understand archive files.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2017 07:12:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-get-logs-from-Linux-or-Windows-servers/m-p/352280#M64573</guid>
      <dc:creator>esix_splunk</dc:creator>
      <dc:date>2017-11-06T07:12:35Z</dc:date>
    </item>
    <item>
      <title>Re: How does Splunk get logs from Linux or Windows servers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-get-logs-from-Linux-or-Windows-servers/m-p/352281#M64574</link>
      <description>&lt;P&gt;Hi cyberportnoc,&lt;BR /&gt;
as suggested by esix, see &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/WhatSplunkcanmonitor"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Data/WhatSplunkcanmonitor&lt;/A&gt;.&lt;/P&gt;

&lt;P&gt;The easiest way is to install a Universal forwarder on you server to monitor and deploy on each one two Technical Add-Ons (TAs):&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;for Windows servers &lt;A href="https://splunkbase.splunk.com/app/742/"&gt;https://splunkbase.splunk.com/app/742/&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;for Linux servers &lt;A href="https://splunkbase.splunk.com/app/833/"&gt;https://splunkbase.splunk.com/app/833/&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;In these TAs you can find all the scripts and monitoring stanzas to monitor all your servers.&lt;BR /&gt;
The only activity you have to do is choose what do you need (wineventogs, processes, installed softwares, perfmon, etc...) and enable the related stanzas of inputs.conf changing disabled=1 in disabled=0 in the requested stanzas.&lt;/P&gt;

&lt;P&gt;I have only two recommendations:&lt;BR /&gt;
- analyze your requests before start your activity because you could have too logs and exceed your license;&lt;BR /&gt;
- if you have to configure a production environment with many servers use a Deployment Server to deploy TAs in your monitored servers ( &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.0/Updating/Aboutdeploymentserver"&gt;http://docs.splunk.com/Documentation/Splunk/7.0.0/Updating/Aboutdeploymentserver&lt;/A&gt; ).&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2017 07:55:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-get-logs-from-Linux-or-Windows-servers/m-p/352281#M64574</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-11-06T07:55:31Z</dc:date>
    </item>
  </channel>
</rss>

