<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to configure logs capture in Splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-logs-capture-in-Splunk/m-p/207307#M96347</link>
    <description>&lt;P&gt;Hi Skoelpin,&lt;/P&gt;

&lt;P&gt;Is there any documentation with step by step process. I read the document but still not understanding how to proceed. &lt;/P&gt;</description>
    <pubDate>Mon, 26 Sep 2016 09:57:35 GMT</pubDate>
    <dc:creator>thambijoseph</dc:creator>
    <dc:date>2016-09-26T09:57:35Z</dc:date>
    <item>
      <title>How to configure logs capture in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-logs-capture-in-Splunk/m-p/207303#M96343</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
I am a newbie to splunk and I have a requirement like below.&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;We are using Weblogic em console to see and download our web application journey logs. &lt;/LI&gt;
&lt;LI&gt;Now as part of our requirement, we need to use Splunk for the logs capturing. &lt;/LI&gt;
&lt;LI&gt;I am not understanding how to start in using the Splunk. I read some documentation on Splunk but did not got any idea where to start from. &lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Can you please help me out in using Splunk. &lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Joseph.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2016 11:50:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-logs-capture-in-Splunk/m-p/207303#M96343</guid>
      <dc:creator>thambijoseph</dc:creator>
      <dc:date>2016-09-23T11:50:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure logs capture in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-logs-capture-in-Splunk/m-p/207304#M96344</link>
      <description>&lt;P&gt;Hi there, &lt;/P&gt;

&lt;P&gt;Just go to &lt;STRONG&gt;Settings&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Data Inputs&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Files &amp;amp; Directories&lt;/STRONG&gt; OR select how to index your input according to your data source. After that, just follow the wizard.&lt;/P&gt;

&lt;P&gt;If you have any doubt, don't hasitate.&lt;/P&gt;

&lt;P&gt;This will probably help you a lot more, &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.3/Data/Configureyourinputs"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.3/Data/Configureyourinputs&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2016 13:01:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-logs-capture-in-Splunk/m-p/207304#M96344</guid>
      <dc:creator>alemarzu</dc:creator>
      <dc:date>2016-09-23T13:01:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure logs capture in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-logs-capture-in-Splunk/m-p/207305#M96345</link>
      <description>&lt;P&gt;Welcome to Splunk Answers @thambijoseph&lt;/P&gt;

&lt;P&gt;Splunk is a tool which will ingest logs, index them, parse them, then make them available in a nice user interface which is easy to search and make use it. You can also create fields and use those fields to analyze data and make sense of it. &lt;/P&gt;

&lt;P&gt;To start you will need to have a remote host file and monitor a directory where the log files are being generated. Once new data flows into the log files, Splunk will see this and forward them to your indexer which will then index the files. Assuming your indexer is already set up, your first step would be to create an &lt;CODE&gt;inputs.conf&lt;/CODE&gt; on the remote host and start monitoring a directory to ingest those log files. &lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2016 13:13:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-logs-capture-in-Splunk/m-p/207305#M96345</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2016-09-23T13:13:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure logs capture in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-logs-capture-in-Splunk/m-p/207306#M96346</link>
      <description>&lt;P&gt;Hi Alemarzu,&lt;/P&gt;

&lt;P&gt;Is there any documentation with step by step process. I read the document but still not understanding how to proceed. &lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2016 09:57:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-logs-capture-in-Splunk/m-p/207306#M96346</guid>
      <dc:creator>thambijoseph</dc:creator>
      <dc:date>2016-09-26T09:57:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure logs capture in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-logs-capture-in-Splunk/m-p/207307#M96347</link>
      <description>&lt;P&gt;Hi Skoelpin,&lt;/P&gt;

&lt;P&gt;Is there any documentation with step by step process. I read the document but still not understanding how to proceed. &lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2016 09:57:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-logs-capture-in-Splunk/m-p/207307#M96347</guid>
      <dc:creator>thambijoseph</dc:creator>
      <dc:date>2016-09-26T09:57:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure logs capture in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-logs-capture-in-Splunk/m-p/207308#M96348</link>
      <description>&lt;P&gt;Hi there mate, sure there is.&lt;/P&gt;

&lt;P&gt;In the link that pasted above from Splunk docs if you look at the left side of the web page, you'll see this menu. In there you will find the step by step procedure to index your data.&lt;BR /&gt;
&lt;IMG src="https://i.imgsafe.org/9169f94ed9.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2016 12:36:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-logs-capture-in-Splunk/m-p/207308#M96348</guid>
      <dc:creator>alemarzu</dc:creator>
      <dc:date>2016-09-26T12:36:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure logs capture in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-logs-capture-in-Splunk/m-p/207309#M96349</link>
      <description>&lt;P&gt;The below link describes how to start indexing data. &lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.3/Data/Getstartedwithgettingdatain"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.3/Data/Getstartedwithgettingdatain&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Here's a brief description to add onto this.. This is an example of a general setup..&lt;BR /&gt;
You will have a remote server which will generate log data.. This log data will be under &lt;CODE&gt;C:\Logs\Data.txt&lt;/CODE&gt;.. You will set up a Splunk forwarder to monitor the path &lt;CODE&gt;C:\Logs\Data.txt&lt;/CODE&gt; so everytime new data is added to the text file &lt;CODE&gt;Data.txt&lt;/CODE&gt;, the Splunk forwarder will recognize this and forward it to your central Splunk server (Also known as an indexer) and the indexer will index and parse the data and make it usable in the Splunk GUI. So say &lt;CODE&gt;Data.txt&lt;/CODE&gt; is a high volume log which has millions of events and you want to know how often people have attempted search for the term "splunk", you could do a search and quickly find out how many people looked for Splunk compared to all the other terms overall. So to set this up, you will need to configure your forwarder on the remote machine. After installing the forwarder, you will need 2 files which will be located in &lt;CODE&gt;%SPLUNK_HOME%/etc/system/local&lt;/CODE&gt;.. Those 2 files are &lt;CODE&gt;inputs.conf&lt;/CODE&gt; which will have a stanza and define what index your data will go to and the sourcetype it should have (When you create fields in Splunk , it will be relative to the sourcetype) and an &lt;CODE&gt;outputs.conf&lt;/CODE&gt; will have information which will point to your indexer so the data knows where to go. It's super easy to install a forwarder and you can look at examples online for the &lt;CODE&gt;inputs.conf&lt;/CODE&gt; and &lt;CODE&gt;outputs.conf&lt;/CODE&gt; and copy those then you should be in business &lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2016 13:13:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-logs-capture-in-Splunk/m-p/207309#M96349</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2016-09-26T13:13:44Z</dc:date>
    </item>
  </channel>
</rss>

