<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to collect data from directories on remote machine into splunk indexer in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-data-from-directories-on-remote-machine-into/m-p/129141#M97754</link>
    <description>&lt;P&gt;You're welcome. Now you can show your support and accept the answer and/or upvote it &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; thx &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 30 Jan 2014 07:30:30 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2014-01-30T07:30:30Z</dc:date>
    <item>
      <title>How to collect data from directories on remote machine into splunk indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-data-from-directories-on-remote-machine-into/m-p/129130#M97743</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have directories residing on D drive on my remote machine.&lt;/P&gt;

&lt;P&gt;I have a splunk machine using which I need to collect the data from the directory on D drive on remote machine.&lt;/P&gt;

&lt;P&gt;I had installed universal forwarder on the remote machine, but it does not help me to fetch out the information from D drive. I can fetch the data only from the eventlogs of remote machine.&lt;/P&gt;

&lt;P&gt;Kindly help!&lt;/P&gt;

&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;
Sushma.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2014 09:09:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-data-from-directories-on-remote-machine-into/m-p/129130#M97743</guid>
      <dc:creator>sushma7</dc:creator>
      <dc:date>2014-01-29T09:09:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to collect data from directories on remote machine into splunk indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-data-from-directories-on-remote-machine-into/m-p/129131#M97744</link>
      <description>&lt;P&gt;Hi sushma7,&lt;/P&gt;

&lt;P&gt;best is to start reading the docs about &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/Monitorfilesanddirectories"&gt;Monitor files and directories&lt;/A&gt; and on &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/Editinputs.conf"&gt;edit inputs.conf&lt;/A&gt;. Remember this must all be done on your universal forwarder where your D drive exists. &lt;/P&gt;

&lt;P&gt;hope this helps ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2014 09:24:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-data-from-directories-on-remote-machine-into/m-p/129131#M97744</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-01-29T09:24:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to collect data from directories on remote machine into splunk indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-data-from-directories-on-remote-machine-into/m-p/129132#M97745</link>
      <description>&lt;P&gt;Thanks for your information!&lt;/P&gt;

&lt;P&gt;If i edit the inputs.conf file on the universal forwarder machine. Will I be able to view the D drive of remote machine from the main splunk machine i.e under Files and Directories- Add New option? Generally it shows the drives of the local machine right?&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Sushma.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2014 09:38:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-data-from-directories-on-remote-machine-into/m-p/129132#M97745</guid>
      <dc:creator>sushma7</dc:creator>
      <dc:date>2014-01-29T09:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to collect data from directories on remote machine into splunk indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-data-from-directories-on-remote-machine-into/m-p/129133#M97746</link>
      <description>&lt;P&gt;yes, in the UI of the indexer you will only see the local directories and files. You must manually edit the inputs.conf on the remote universal forwarder, this tells the forwarder to monitor the data and forward it to the indexer. Nevertheless, you will still not see this D drive in your indexer UI &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2014 09:46:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-data-from-directories-on-remote-machine-into/m-p/129133#M97746</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-01-29T09:46:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to collect data from directories on remote machine into splunk indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-data-from-directories-on-remote-machine-into/m-p/129134#M97747</link>
      <description>&lt;P&gt;As you have said, I had changed the inputs.conf file on the   remote universal forwarder and here is what I did.&lt;BR /&gt;
1)I want to monitor D:\Test\Testscripts (folder) on remote machine.&lt;BR /&gt;
2) So i added the following lines on the E:\SplunkUniversalForwarder\etc\system\local\inputs.conf file. The lines are as follows:&lt;/P&gt;

&lt;P&gt;[monitor://D:\Test\Testscripts]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
sourcetype = access_combined&lt;/P&gt;

&lt;P&gt;3) Then I logged into the main splunk instance, now I should be able to view the directory right? I am still facing issues. Still should I make anymore changes?&lt;/P&gt;

&lt;P&gt;Can you correct me if i was wrong somewhere.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2014 14:06:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-data-from-directories-on-remote-machine-into/m-p/129134#M97747</guid>
      <dc:creator>sushma7</dc:creator>
      <dc:date>2014-01-29T14:06:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to collect data from directories on remote machine into splunk indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-data-from-directories-on-remote-machine-into/m-p/129135#M97748</link>
      <description>&lt;P&gt;Did you restart the universal forwarder after the file change? Can the user running splunk access this directory? What is your issues?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2014 14:10:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-data-from-directories-on-remote-machine-into/m-p/129135#M97748</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-01-29T14:10:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to collect data from directories on remote machine into splunk indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-data-from-directories-on-remote-machine-into/m-p/129136#M97749</link>
      <description>&lt;P&gt;I had restarted the forwarder service from services.msc&lt;BR /&gt;
Then i logged into the main splunk instance and under the search and reporting app I ran the query sourcetpe = access_combined,because this is what I mentioned in the inputs.conf, but I could not view the data that I intended to monitor.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2014 14:26:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-data-from-directories-on-remote-machine-into/m-p/129136#M97749</guid>
      <dc:creator>sushma7</dc:creator>
      <dc:date>2014-01-29T14:26:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to collect data from directories on remote machine into splunk indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-data-from-directories-on-remote-machine-into/m-p/129137#M97750</link>
      <description>&lt;P&gt;check 'index=_internal' for any message related to your universal forwarder&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2014 14:33:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-data-from-directories-on-remote-machine-into/m-p/129137#M97750</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-01-29T14:33:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to collect data from directories on remote machine into splunk indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-data-from-directories-on-remote-machine-into/m-p/129138#M97751</link>
      <description>&lt;P&gt;Yep I would, one more query, the directory that i mentioned in the inputs.conf is not a static one, the files in it gets updated for every 4 hours, so it would get updated in splunk as well right?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2014 14:43:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-data-from-directories-on-remote-machine-into/m-p/129138#M97751</guid>
      <dc:creator>sushma7</dc:creator>
      <dc:date>2014-01-29T14:43:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to collect data from directories on remote machine into splunk indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-data-from-directories-on-remote-machine-into/m-p/129139#M97752</link>
      <description>&lt;P&gt;Yes if you monitor a directory Splunk will read everything in there if you did not set any black/whitelists which you did not &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2014 14:48:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-data-from-directories-on-remote-machine-into/m-p/129139#M97752</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-01-29T14:48:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to collect data from directories on remote machine into splunk indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-data-from-directories-on-remote-machine-into/m-p/129140#M97753</link>
      <description>&lt;P&gt;Thanks for your support! It worked out....hurray!!!!!&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2014 06:33:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-data-from-directories-on-remote-machine-into/m-p/129140#M97753</guid>
      <dc:creator>sushma7</dc:creator>
      <dc:date>2014-01-30T06:33:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to collect data from directories on remote machine into splunk indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-data-from-directories-on-remote-machine-into/m-p/129141#M97754</link>
      <description>&lt;P&gt;You're welcome. Now you can show your support and accept the answer and/or upvote it &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; thx &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2014 07:30:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-collect-data-from-directories-on-remote-machine-into/m-p/129141#M97754</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-01-30T07:30:30Z</dc:date>
    </item>
  </channel>
</rss>

