Getting Data In

Can I collect Linux application logs with no UF installed?

dionrivera
Communicator

I have a linux box that is very sensitive to agent overhead, resources, security, etc. Installing the UF on it is out of the question. However, I need to pull some nginx application logs. How can I accomplish this?  I tried searching for answers here and other places but I don't see a comprehensive answer.
Thank you in advance.

Labels (2)
0 Karma
1 Solution

dionrivera
Communicator

As it turns out. I was able to use rsyslog. Created a configuration file in /etc/rsyslogd and enabled the "imfile" module in /etc/rsyslog.conf.

View solution in original post

0 Karma

dionrivera
Communicator

As it turns out. I was able to use rsyslog. Created a configuration file in /etc/rsyslogd and enabled the "imfile" module in /etc/rsyslog.conf.

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...