All Apps and Add-ons

Imported logs not showing

appmandan
Path Finder

I have set up an FTP server on my splunk indexer so that our AS400 and FTP over log files. I have set up under "Files & Directories" in Splunk Manager a rule to continuously collect from the the same folder as the AS400 is FTPing the log file in. I'm not getting the log messages into Splunk or Splunk for AS/400. I have set the sourcetype to iseries and also tried dspjrn:5 and have verified the destination index is iseries. I'm still not able to pull in the logs. Does the log file itself need a specific name? The filename I'm trying to pull in is jern.jern. Any ideas?

Thanks

0 Karma
1 Solution

appmandan
Path Finder

This was a formatting error on the AS/400 logs before they were sent over

View solution in original post

appmandan
Path Finder

This was a formatting error on the AS/400 logs before they were sent over

appmandan
Path Finder

I went to Splunk Manager from the AS/400 app.

0 Karma

gnovak
Builder

Did you put the inputs into the correct app? What app were you in when you went to Manager and added the inputs?

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...