Getting Data In

Alfresco logs to Splunk Cloud

anandhalagaras1
Contributor

Our Servers are located in Private Subnets in EC2 instances on AWS. The Platform/Software that we are using is called Alfresco which produces log files named ‘alfresco.log’, which I wanted to be ingested into Splunk Cloud.

One is a Linux instance in a Private Subnet and the other is a Windows machine in a Private Subnet. They cannot connect to the Internet from within. They can only communicate with the Machines in their VPC.

So can you kindly let us know how to send those logs to the Splunk Cloud..

Tags (1)
0 Karma

mydog8it
Builder

The simple answer here is you need to find a path to the internet from these machines. If the data can't get to the internet, it can't reach SplunkCloud.
If there is an egress point in another VPC to the internet or from your on-prem environment the data can get to SplunkCloud by installing the universal forwarder on the source machines and opening a path to the internet for these boxes to follow.
If you can not have these boxes communicating directly out, perhaps you need to consider an intermediate tier of forwarders that have access to internal/AWS resources and can talk to the internet. Then your data sources can send the logs to the intermediate forwarder tier which can then send the data along to SplunkCloud.

0 Karma

anandhalagaras1
Contributor

Can you kindly help on my request.

0 Karma

anandhalagaras1
Contributor

Thank you for your response.

So now the requester have created a ngnix box and which is how we can connect to Splunk instance over the internet.

So how can we receive the logs now into Splunk Cloud ? Can you kindly let me know.

So from nginx how can we send the logs to splunk cloud.

0 Karma

anandhalagaras1
Contributor

Can you kindly help on my request.

0 Karma

anandhalagaras1
Contributor

Thank you for your response.

So now the requester have created a ngnix box and which is how we can connect to Splunk instance over the internet.

So how can we receive the logs now into Splunk Cloud ? Can you kindly let me know.

0 Karma

anandhalagaras1
Contributor

So from nginx how can we send the logs to splunk cloud.

0 Karma

anandhalagaras1
Contributor

Hi Team,

Can anyone help on the request.

0 Karma

anandhalagaras1
Contributor

Hi All,

Can anyone help on my request.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...