Getting Data In

Can Splunk behave like a batch job or Windows service which will check for a file at ftp location every hour and index that file?

birarich
Explorer

Can Splunk behave like a batch job or like windows service which will check for file at ftp location every hour and index that file?

Tags (3)
0 Karma

acharlieh
Influencer

You could setup a Scripted Input to run a script every hour, perform whatever FTP you need, and index the results.

Scripted inputs are kicked off by Splunk on an interval, configured in inputs.conf. Now it'd be up to you to either write or find an appropriate script to kick off on the regular basis to get you want in this case.

Alternatively if you have access to the OS running the FTP server, you could put a Splunk forwarder on the FTP server and monitor the file that with built in monitor inputs.

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...