<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forwarding Azure App Service Logs do SPlunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-Azure-App-Service-Logs-do-SPlunk/m-p/447212#M77781</link>
    <description>&lt;P&gt;the ftp is not a bad idea actually, try this app out if possible -  &lt;A href="https://splunkbase.splunk.com/app/3318/#/details"&gt;https://splunkbase.splunk.com/app/3318/#/details&lt;/A&gt;  or this  -  &lt;A href="https://splunkbase.splunk.com/app/3534/"&gt;https://splunkbase.splunk.com/app/3534/&lt;/A&gt; ?&lt;BR /&gt;
Is it possible to call them over some sort of API service? Then you can rest ingest them in splunk&lt;/P&gt;</description>
    <pubDate>Sat, 04 May 2019 18:42:23 GMT</pubDate>
    <dc:creator>Sukisen1981</dc:creator>
    <dc:date>2019-05-04T18:42:23Z</dc:date>
    <item>
      <title>Forwarding Azure App Service Logs do SPlunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-Azure-App-Service-Logs-do-SPlunk/m-p/447211#M77780</link>
      <description>&lt;P&gt;I have an azure app service with CUSTOM text log files (stored locally in app service filesystem). How can I index them in splunk?&lt;BR /&gt;
I was thinking about the following, but none was working:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;using azure file storage (samba ports are blocked)&lt;/LI&gt;
&lt;LI&gt;read logs in splunk via ftp (as far as I know impossible)&lt;/LI&gt;
&lt;LI&gt;trying to install splunk forwarder (as far as I know possible only in azure VM, not app service)&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Sat, 04 May 2019 12:38:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-Azure-App-Service-Logs-do-SPlunk/m-p/447211#M77780</guid>
      <dc:creator>mochocki</dc:creator>
      <dc:date>2019-05-04T12:38:28Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding Azure App Service Logs do SPlunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-Azure-App-Service-Logs-do-SPlunk/m-p/447212#M77781</link>
      <description>&lt;P&gt;the ftp is not a bad idea actually, try this app out if possible -  &lt;A href="https://splunkbase.splunk.com/app/3318/#/details"&gt;https://splunkbase.splunk.com/app/3318/#/details&lt;/A&gt;  or this  -  &lt;A href="https://splunkbase.splunk.com/app/3534/"&gt;https://splunkbase.splunk.com/app/3534/&lt;/A&gt; ?&lt;BR /&gt;
Is it possible to call them over some sort of API service? Then you can rest ingest them in splunk&lt;/P&gt;</description>
      <pubDate>Sat, 04 May 2019 18:42:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-Azure-App-Service-Logs-do-SPlunk/m-p/447212#M77781</guid>
      <dc:creator>Sukisen1981</dc:creator>
      <dc:date>2019-05-04T18:42:23Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding Azure App Service Logs do SPlunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-Azure-App-Service-Logs-do-SPlunk/m-p/447213#M77782</link>
      <description>&lt;P&gt;Thanks, I'll try. &lt;BR /&gt;
What do you mean by "call them over some sort of API service"?&lt;/P&gt;</description>
      <pubDate>Sat, 04 May 2019 18:58:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-Azure-App-Service-Logs-do-SPlunk/m-p/447213#M77782</guid>
      <dc:creator>mochocki</dc:creator>
      <dc:date>2019-05-04T18:58:07Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding Azure App Service Logs do SPlunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-Azure-App-Service-Logs-do-SPlunk/m-p/447214#M77783</link>
      <description>&lt;P&gt;i mean can you read the logs through an bash/python/shell script? Then you could create a scripted input and index the output of the script into splunk&lt;/P&gt;</description>
      <pubDate>Sat, 04 May 2019 20:39:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-Azure-App-Service-Logs-do-SPlunk/m-p/447214#M77783</guid>
      <dc:creator>Sukisen1981</dc:creator>
      <dc:date>2019-05-04T20:39:52Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding Azure App Service Logs do SPlunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-Azure-App-Service-Logs-do-SPlunk/m-p/447215#M77784</link>
      <description>&lt;P&gt;In fact none of these addons are good enough. FTP Receiver sets up local ftp server instead of reading logs from remote one. The other addon can only rean diagnostic logs.&lt;BR /&gt;
Can you provide more info about the scripts? Do they run on splunk server? Can they work realtime? I have daily rolling text files but I would like to have them indexed realtime not only after they are rolled.&lt;BR /&gt;
Do you have any examples of such script?&lt;/P&gt;</description>
      <pubDate>Sun, 05 May 2019 09:24:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-Azure-App-Service-Logs-do-SPlunk/m-p/447215#M77784</guid>
      <dc:creator>mochocki</dc:creator>
      <dc:date>2019-05-05T09:24:18Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding Azure App Service Logs do SPlunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-Azure-App-Service-Logs-do-SPlunk/m-p/447216#M77785</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;
Firstly, you have to bear with me , I have 0 experience on azure and a newbie on AWS so I am probably not able to understand simple things in azure.&lt;BR /&gt;
Please see this  - &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.6/Data/MonitorWMIdata#Security_and_remote_access_considerations"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.6/Data/MonitorWMIdata#Security_and_remote_access_considerations&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Can you open cmd on your local and curl into the remote machine to read the log files? If you can then we can always set up a script , key thing is NOT the indexing here, but how you connect from your local to your remote instance AND download the log info from the remote machine.&lt;BR /&gt;
I suggest you google a bit on pyhton or shell or curl command/scripts on how to connect and get logs from a remote azure instance. After that its a cakewalk and I can guide you in that but firstly, can you (you have to, if your splunk is on a different instance than the remote azure instance)  gather the logs from the remote instance to your local?&lt;/P&gt;</description>
      <pubDate>Sun, 05 May 2019 10:51:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-Azure-App-Service-Logs-do-SPlunk/m-p/447216#M77785</guid>
      <dc:creator>Sukisen1981</dc:creator>
      <dc:date>2019-05-05T10:51:58Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding Azure App Service Logs do SPlunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-Azure-App-Service-Logs-do-SPlunk/m-p/447217#M77786</link>
      <description>&lt;P&gt;You need to send your logs to app fabric, table, blob, or eventhub then pull the data using other Microsoft cloud services app from splunk.  Note it doesnt support event hubs but you can send event hub to blob storage and read from there.&lt;/P&gt;</description>
      <pubDate>Sun, 05 May 2019 11:39:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-Azure-App-Service-Logs-do-SPlunk/m-p/447217#M77786</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2019-05-05T11:39:50Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding Azure App Service Logs do SPlunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-Azure-App-Service-Logs-do-SPlunk/m-p/447218#M77787</link>
      <description>&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/3110/"&gt;https://splunkbase.splunk.com/app/3110/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 05 May 2019 11:40:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-Azure-App-Service-Logs-do-SPlunk/m-p/447218#M77787</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2019-05-05T11:40:38Z</dc:date>
    </item>
  </channel>
</rss>

