Monitoring Splunk

How to monitor Application logs of COTS Application?

kamraatul
Engager

If we want to use the Splunk as Central log monitoring tools how can we monitor the COTS application logs in Splunk?

Labels (1)
Tags (1)
0 Karma

kamraatul
Engager

Thanks for sharing he information.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

There is no one way to do that.  It all depends on the application and how that application makes its data available to Splunk.  Many COTS applications have apps available at splunkbase.splunk.com.  Start there.

If there is no app available, you'll have to do the job yourself.  There are a few ways to onboard data into Splunk.

Install a universal forwarder on the server to send log files to Splunk
Have the server send syslog data to Splunk via a syslog server or Splunk Connect for Syslog
Use the server's API to extract data for indexing
Use Splunk DB Connect to pull data from the server's SQL database.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...