<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTP Server Logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/FTP-Server-Logs/m-p/38451#M7087</link>
    <description>&lt;P&gt;You have a splunk forwarder on the FTP server currently?  That is the most straightforward way to monitor any logs on that or any server. Is there an issue or are you just looking for another way?&lt;/P&gt;</description>
    <pubDate>Fri, 17 Aug 2012 19:03:24 GMT</pubDate>
    <dc:creator>sdaniels</dc:creator>
    <dc:date>2012-08-17T19:03:24Z</dc:date>
    <item>
      <title>FTP Server Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/FTP-Server-Logs/m-p/38450#M7086</link>
      <description>&lt;P&gt;How would i configure Splunk to input all FTP logs from my Splunk server? Anybody have any suggestions on what they do, or Splunk documenation on this topic. (At this point all of the logs will be sent to the Splunk server via univeral forwarder)&lt;/P&gt;</description>
      <pubDate>Fri, 17 Aug 2012 18:25:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/FTP-Server-Logs/m-p/38450#M7086</guid>
      <dc:creator>Michael_Schyma1</dc:creator>
      <dc:date>2012-08-17T18:25:54Z</dc:date>
    </item>
    <item>
      <title>Re: FTP Server Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/FTP-Server-Logs/m-p/38451#M7087</link>
      <description>&lt;P&gt;You have a splunk forwarder on the FTP server currently?  That is the most straightforward way to monitor any logs on that or any server. Is there an issue or are you just looking for another way?&lt;/P&gt;</description>
      <pubDate>Fri, 17 Aug 2012 19:03:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/FTP-Server-Logs/m-p/38451#M7087</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-08-17T19:03:24Z</dc:date>
    </item>
    <item>
      <title>Re: FTP Server Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/FTP-Server-Logs/m-p/38452#M7088</link>
      <description>&lt;P&gt;What ftpd are we talking about? Do you have log samples?&lt;/P&gt;</description>
      <pubDate>Fri, 17 Aug 2012 20:27:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/FTP-Server-Logs/m-p/38452#M7088</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-08-17T20:27:53Z</dc:date>
    </item>
    <item>
      <title>Re: FTP Server Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/FTP-Server-Logs/m-p/38453#M7089</link>
      <description>&lt;P&gt;if the logs are in the same server in the folder &lt;BR /&gt;
/mylog/ftp/ and look like myftp.log (or myftp.log.1 or myftp.log.2.gz etc...)&lt;/P&gt;

&lt;P&gt;Collect a sample and index it using the manager, it will help you figure the best sourcetype configuration (linebreak parsing, timestamp detection...)&lt;/P&gt;

&lt;P&gt;Then once done create a monitor input on the folder/logfile using the manager or the configuration file.&lt;BR /&gt;
[monitor:///mylog/ftp/myftp.*]&lt;BR /&gt;
sourcetype=mysourcetypefortmyftp&lt;/P&gt;

&lt;P&gt;If the log files are not on the same server than your splunk indexer, then you can install the universal forwarder as an agent on the box that has the logs (and make sure to define the sourcetype in props.conf on the indexer).&lt;BR /&gt;
Or an alternative is to use a network mount for the log folder no the splunk indexer.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Aug 2012 03:16:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/FTP-Server-Logs/m-p/38453#M7089</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2012-08-20T03:16:21Z</dc:date>
    </item>
  </channel>
</rss>

