If we want to use the Splunk as Central log monitoring tools how can we monitor the COTS application logs in Splunk?
Thanks for sharing he information.
There is no one way to do that. It all depends on the application and how that application makes its data available to Splunk. Many COTS applications have apps available at splunkbase.splunk.com. Start there.
If there is no app available, you'll have to do the job yourself. There are a few ways to onboard data into Splunk.
Install a universal forwarder on the server to send log files to Splunk
Have the server send syslog data to Splunk via a syslog server or Splunk Connect for Syslog
Use the server's API to extract data for indexing
Use Splunk DB Connect to pull data from the server's SQL database.