Getting Data In

Is it possible to read and monitor Windows server files from a Linux Heavy Forwarder?

reswob4
Builder

I have an environment where it's going to be a hassle to add a new Windows server. However, we have a file on a Windows server we would like to monitor and log. Is it possible to do that from a Linux Heavy Forwarder? Using samba/cifs so we can map the drive?

Or, as this answer implies

( https://answers.splunk.com/answers/27269/using-fschange-to-monitor-files-on-linux-server-from-window... ),

will that cause more problems then it's worth?

Thanks.

0 Karma

adonio
Ultra Champion

Hello,
you can install a windows forwarder on that server and monitor the file and send it straight to your linux splunk heavy forwarder, or directly to the indexer tier
hope it helps

0 Karma

reswob4
Builder

Thanks, but (and I should have mentioned this in the original post) I am not permitted to install a windows forwarder on the windows server. Hence the question about the work around.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...