My splunk instance is currently monitoring a local file and indexing .csv files as they are added. I need to move this file to an online site. So, given that I have a URL to a folder or file, how would I configure Splunk to monitor the online directory in a similiar fashion to monitoring a local directory?
I'm pretty new to Splunk so am not very familiar with the REST API or setting up a Splunk forwarder. Any input would be greatly appreciated. Thanks!
If you have access to the site that will store the files, I recommend installing a Splunk Universal Forwarder. The forwarder will monitor the file in the same way Splunk is doing for you now and send the contents to your indexer(s). Installing a forwarder is very simple. See the docs at http://docs.splunk.com/Documentation/Splunk/6.2.4/Forwarding/Aboutforwardingandreceivingdata.