Monitoring Splunk

How to monitor Application logs of COTS Application?

kamraatul
Engager

If we want to use the Splunk as Central log monitoring tools how can we monitor the COTS application logs in Splunk?

Labels (1)
Tags (1)
0 Karma

kamraatul
Engager

Thanks for sharing he information.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

There is no one way to do that.  It all depends on the application and how that application makes its data available to Splunk.  Many COTS applications have apps available at splunkbase.splunk.com.  Start there.

If there is no app available, you'll have to do the job yourself.  There are a few ways to onboard data into Splunk.

Install a universal forwarder on the server to send log files to Splunk
Have the server send syslog data to Splunk via a syslog server or Splunk Connect for Syslog
Use the server's API to extract data for indexing
Use Splunk DB Connect to pull data from the server's SQL database.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...