Monitoring Splunk

splunk search head

Siddharthnegi
Contributor

Can i monitor a file in search head?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Siddharthnegi,

yes, it's unusual (usual logs are read by Universal or Heavy Forwarders), but it's possible.

Remember that anyway, it's a best practice to forward all SH logs to the Indexers, so for this reason it's possible.

Ciao.

Giuseppe

0 Karma

Siddharthnegi
Contributor

thanks for the reply can you tell me how can i do that

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...