Monitoring Splunk

Indexing zip files

sameer12sa
Engager

Hi

I am a new user, who downloaded splunk yesterday and learning to configure for monitoring and searching our production logs.
I have a few questions.
Is there any documentation link where I can find how to configure a splunk host to monitor log files from different hosts on the same network which are linux boxes.
I also need some documentation to configure splunk to search log files.
I have a question regarding indexing zip files. Actually the cron job will zip all the previous log files and keep the log files in the same directory.

Can we have the zip files and current log files in the same directory? Or the rotated zip files should be in different directory.

Thanks
Sameer

Tags (1)
0 Karma

sameer12sa
Engager

Thanks for the quick response.
I am able to successfully configure Splunk Search.

0 Karma

ChrisG
Splunk Employee
Splunk Employee

Start with the Getting Data In Manual. It explains how to get data from files and directories, configure event types and source types, and introduces the subject of getting data in a distributed environment.

0 Karma

bbingham
Builder

Sameer, here's the answers to your questions:

  1. About Forwarders
  2. I'm confused on how you mean to search log files, just how to search in splunk in general? Check out the "Getting Started" app inside splunk after you've installed it.
  3. There are a number of ways to deal with this, you can create blacklists to exclude the zips, or you can place them in their own directory. This really becomes your personal choice. Check this link out: Whitelist/Blacklist Incoming Data
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...