How to setup / migrate a few Web server logs into Splunk. I need to set Splunk to ingest some web server logs into Splunk. Need step by step, if someone can help please
try to follow these preliminary steps:
To take logs you can use:
in the first case
In the second case you have to:
disabled = false
sourcetype = ms:iis:auto
index = <preferred index>
I hint always the first one!
To better understand how to do this you can see https://docs.splunk.com/Documentation/Splunk/8.1.2/Data/Getstartedwithgettingdatain
there are also some interesting videos in YouTube to do this.