Deployment Architecture

What is simplest way to periodically fetch new lines from a remote apache access log file to a Splunk server without a static IP??

boris
Path Finder

My main Splunk web server application is running on my local Mac, http://localhost:8000/.

Since this main Splunk server that needs to injest a Apache access log file doesnt have a static IP address, I cant use the Universal Forwarder.

What is the simplest way to periodically injest new events from a remote Apache access log file, which I have ssh and scp access to (my guess is rsync, but perhaps there are pros can cons to other approaches that I am unaware of).

Tags (3)
0 Karma

yannK
Splunk Employee
Splunk Employee
  • install an universal forwarder ... ok not possible, but so much simpler.
  • You can setup a syslog / rsyslog to forward the logs to your splunk indexer.
  • if you can have a static hostname (or use a dnsredirect like no-ip)
    • mount the vol folder on the indexer and monitor it
    • write a script to connect to your remote server and rsync / scp the files to a local monitored folder
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...