<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is the best way to transfer logs to splunk for monitoring? in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/What-is-the-best-way-to-transfer-logs-to-splunk-for-monitoring/m-p/64766#M1495</link>
    <description>&lt;P&gt;The best option is to install a universal forwarder on the server, where the logs are generated.  The forwarder can send the logs to the indexer (your primary Splunk server).&lt;/P&gt;</description>
    <pubDate>Mon, 18 Mar 2013 08:32:12 GMT</pubDate>
    <dc:creator>sbrant_splunk</dc:creator>
    <dc:date>2013-03-18T08:32:12Z</dc:date>
    <item>
      <title>What is the best way to transfer logs to splunk for monitoring?</title>
      <link>https://community.splunk.com/t5/Reporting/What-is-the-best-way-to-transfer-logs-to-splunk-for-monitoring/m-p/64764#M1493</link>
      <description>&lt;P&gt;My Use case:&lt;BR /&gt;
1- I have a log file X ( a log generated from a web applications - errors.log ) that exist on a server A &lt;BR /&gt;
2- Splunk is installed on server B&lt;BR /&gt;
In order to monitor this logs, one solution 1 is to send the file X to splunk server B and then used the monitor options in inputs.conf file.&lt;/P&gt;

&lt;P&gt;I was wondering if an alternative solution 2 could work in order to monitor this log. I need to know if i can use splunk universal forwarder to monitor the log on another machine but i don't know the step yet. &lt;/P&gt;

&lt;P&gt;Another solution 3 i'm thinking of is to sent the logs to splunk server by email but i don't actually know if that could work. &lt;/P&gt;

&lt;P&gt;Please i need to know if someone have faced this situation before? and what solution is preferable and what are the steps? &lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2013 08:18:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/What-is-the-best-way-to-transfer-logs-to-splunk-for-monitoring/m-p/64764#M1493</guid>
      <dc:creator>royimad</dc:creator>
      <dc:date>2013-03-18T08:18:01Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to transfer logs to splunk for monitoring?</title>
      <link>https://community.splunk.com/t5/Reporting/What-is-the-best-way-to-transfer-logs-to-splunk-for-monitoring/m-p/64765#M1494</link>
      <description>&lt;P&gt;Well that's exactly what the Universal Forwarder is for - reading logs on one system and forwarding them to a Splunk instance on another system.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.2/Deploy/Introducingtheuniversalforwarder"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.2/Deploy/Introducingtheuniversalforwarder&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2013 08:30:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/What-is-the-best-way-to-transfer-logs-to-splunk-for-monitoring/m-p/64765#M1494</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-03-18T08:30:08Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to transfer logs to splunk for monitoring?</title>
      <link>https://community.splunk.com/t5/Reporting/What-is-the-best-way-to-transfer-logs-to-splunk-for-monitoring/m-p/64766#M1495</link>
      <description>&lt;P&gt;The best option is to install a universal forwarder on the server, where the logs are generated.  The forwarder can send the logs to the indexer (your primary Splunk server).&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2013 08:32:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/What-is-the-best-way-to-transfer-logs-to-splunk-for-monitoring/m-p/64766#M1495</guid>
      <dc:creator>sbrant_splunk</dc:creator>
      <dc:date>2013-03-18T08:32:12Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to transfer logs to splunk for monitoring?</title>
      <link>https://community.splunk.com/t5/Reporting/What-is-the-best-way-to-transfer-logs-to-splunk-for-monitoring/m-p/64767#M1496</link>
      <description>&lt;P&gt;Thanks, for your answer. should i install a splunk instance on where universal forwarder exist? could i use an open ports for that reason?- Can i perform 2 step forwards ? &lt;BR /&gt;
Machine A with universal forwarder --&amp;gt; Machine B with universal forwarder --&amp;gt; Machine C with Splunk Instance.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2013 08:35:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/What-is-the-best-way-to-transfer-logs-to-splunk-for-monitoring/m-p/64767#M1496</guid>
      <dc:creator>royimad</dc:creator>
      <dc:date>2013-03-18T08:35:08Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to transfer logs to splunk for monitoring?</title>
      <link>https://community.splunk.com/t5/Reporting/What-is-the-best-way-to-transfer-logs-to-splunk-for-monitoring/m-p/64768#M1497</link>
      <description>&lt;P&gt;Thanks, for your answer. should i install a splunk instance on where universal forwarder exist? could i use an open ports for that reason?- Can i perform 2 step forwards ? &lt;BR /&gt;
Machine A with universal forwarder --&amp;gt; Machine B with universal forwarder --&amp;gt; Machine C with Splunk Instance.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2013 08:36:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/What-is-the-best-way-to-transfer-logs-to-splunk-for-monitoring/m-p/64768#M1497</guid>
      <dc:creator>royimad</dc:creator>
      <dc:date>2013-03-18T08:36:04Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to transfer logs to splunk for monitoring?</title>
      <link>https://community.splunk.com/t5/Reporting/What-is-the-best-way-to-transfer-logs-to-splunk-for-monitoring/m-p/64769#M1498</link>
      <description>&lt;P&gt;Not sure what you're after. What do you mean by "use an open port"? What is step 2? Where did machine C come from?&lt;/P&gt;

&lt;P&gt;I recommend that you read through the docs on the Universal Forwarder so you understand what it does and how you can use it. It sounds to me like you're overcomplicating things because you haven't read up on the available options.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2013 09:21:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/What-is-the-best-way-to-transfer-logs-to-splunk-for-monitoring/m-p/64769#M1498</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-03-18T09:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to transfer logs to splunk for monitoring?</title>
      <link>https://community.splunk.com/t5/Reporting/What-is-the-best-way-to-transfer-logs-to-splunk-for-monitoring/m-p/64770#M1499</link>
      <description>&lt;P&gt;My situation is this,on an online production Machine A servers their is errors logs that exist. I need to be able to monitor those logs using the universal forwarder but one of my requirement rules is do not open another port on the server for the splunk forwarder and i need to know if i can use existing opened port. The opened port is for Machine B so i need to know if i can use 2 steps forwards.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2013 09:30:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/What-is-the-best-way-to-transfer-logs-to-splunk-for-monitoring/m-p/64770#M1499</guid>
      <dc:creator>royimad</dc:creator>
      <dc:date>2013-03-18T09:30:41Z</dc:date>
    </item>
  </channel>
</rss>

