Deployment Architecture

What is simplest way to periodically fetch new lines from a remote apache access log file to a Splunk server without a static IP??

boris
Path Finder

My main Splunk web server application is running on my local Mac, http://localhost:8000/.

Since this main Splunk server that needs to injest a Apache access log file doesnt have a static IP address, I cant use the Universal Forwarder.

What is the simplest way to periodically injest new events from a remote Apache access log file, which I have ssh and scp access to (my guess is rsync, but perhaps there are pros can cons to other approaches that I am unaware of).

Tags (3)
0 Karma

yannK
Splunk Employee
Splunk Employee
  • install an universal forwarder ... ok not possible, but so much simpler.
  • You can setup a syslog / rsyslog to forward the logs to your splunk indexer.
  • if you can have a static hostname (or use a dnsredirect like no-ip)
    • mount the vol folder on the indexer and monitor it
    • write a script to connect to your remote server and rsync / scp the files to a local monitored folder
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...