Getting Data In

How to retrieve a file from sFTP and copy to Splunk folder?

manojchacko78
Path Finder

Hi,

I have the system logs being dumped in the sFTP server and would like to access them and move to local folders in Splunk server. Can you please share the script i can use for this?

 

Labels (2)
0 Karma

manojchacko78
Path Finder

Hi @gcusello 

Yes that is correct and got universal forwarder in the sFTP server

It worked now. 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @manojchacko78 ,

let us know if we can help you more, or, please, accept one answer for the other people of Community.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated by all the Contributors 😉

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

maybe this helps you https://github.com/splunk/splunk-add-on-for-sftp-files-downloader

I haven't try it, but basically you should have modular input which do the collection of logs from remote sFTP server.

r. Ismo

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @manojchacko78,

let me understand:

you have an sFTP server with some files that you would read and index in Splunk, is it correct?

have you a Universal Forwarder on this server?

if yes, you don't need to move it, you can create an input and ingest it in Splunk without a copy on another folder or server.

Could you better describe your requirement?

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

What’s New in Splunk Observability Cloud – June 2025

What’s New in Splunk Observability Cloud – June 2025 We are excited to announce the latest enhancements to ...

Almost Too Eventful Assurance: Part 2

Work While You SleepBefore you can rely on any autonomous remediation measures, you need to close the loop ...

Leveraging Detections from the Splunk Threat Research Team & Cisco Talos

 Stay ahead of today’s evolving threats with the combined power of the Splunk Threat Research Team (STRT) and ...