Hi,
I have the system logs being dumped in the sFTP server and would like to access them and move to local folders in Splunk server. Can you please share the script i can use for this?
Hi @manojchacko78 ,
let us know if we can help you more, or, please, accept one answer for the other people of Community.
Ciao and happy splunking
Giuseppe
P.S.: Karma Points are appreciated by all the Contributors 😉
Hi
maybe this helps you https://github.com/splunk/splunk-add-on-for-sftp-files-downloader
I haven't try it, but basically you should have modular input which do the collection of logs from remote sFTP server.
r. Ismo
Hi @manojchacko78,
let me understand:
you have an sFTP server with some files that you would read and index in Splunk, is it correct?
have you a Universal Forwarder on this server?
if yes, you don't need to move it, you can create an input and ingest it in Splunk without a copy on another folder or server.
Could you better describe your requirement?
Ciao.
Giuseppe