Getting Data In

Unpacking and Uploading certain files from an archive automatically/scripted

ValentinM
Engager

What is the best way to get data into Splunk from a zip file (files in different subfolders of the zip) in an automated way?

 

I need to upload certain txt.files from an archive(debug bundle) into my Splunk deployment. The archive gets downloaded on clients that have access to the splunk deployment, and i need a way to automate this process, instead of unpacking the whole archive and then selecting the files i need one by one and uploading them.

 

Any help appreciated.

Labels (3)
0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @ValentinM 

Splunk does the unpacking automatically, configure the monitor pointing to your .zip file in inputs.conf on the host where files exist. You should have UF/HF or standalone Splunk on the host.

This link helps to config sub-directories - Monitor files and directories with inputs.conf - Splunk Documentation

---------------------------

An upvote would be appreciated if it helps!

Tags (1)
0 Karma

ValentinM
Engager

The thing is the .zip file contains multiple hundred files of which i only need about 10 to analyse them in my Splunk Deployment, also sometimes its necessary to download multiple of these .zip files (each zip is a debug bundle of a client pc), and there are multiple users who might download +upload these to Splunk, so if possible i dont want to install a Forwarder on each host.

 

The overall process should be somewhat like this, a authorirized Splunk User downloads the .zip files he wants to analyse manually, so lets say now he has 4 .zip files on his local machine. Now i need a way in Splunk to unpack the files that i want (about 10 out of the 300+ in the .zip), add 1-2 custom fields at index time to them, and upload them in an automated way.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In January, the Splunk Threat Research Team had one release of new security content via the Splunk ES Content ...

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...