Splunk Dev

How to send logs in Windows

bee
New Member

Hi, 

I try to send logs my Windows server to Splunk via Powershell but I have this type of error :   Cannot convert value to type System.String.

This is my code :

# Function to send log files with HEC
function Send-LogToSplunk {
param (
[string]$filePath
)

$logContent = Get-Content -Path $filePath -Raw
$fileName = [System.IO.Path]::GetFileName($filePath)
$fileDirectory = [System.IO.Path]::GetDirectoryName($filePath)

$splunkServer = "$splunkHost/services/collector/event"
$header = @{"Authorization" = "Splunk $splunkToken"}

$payload = @{
event = $logContent
host = $env:COMPUTERNAME
sourcetype = "log"
source = $filePath
} | ConvertTo-Json


#Write-Host "Log Content $logContent";
#Write-Host "Payload to be sent: $payload";
Write-Host "FileDirectory $fileDirectory";

try {

$response = Invoke-RestMethod -Method Post -Uri $splunkServer -Headers $header -Body $payload

Write-Host "Log sent successfully: $fileName"
} catch {
Write-Host "Failed to send log: $filePath Code Error: '$global:errorConnectionCode'"
Write-Host "Error details: $_"
Exit $global:errorConnectionCode
}
}

Thanks in advance

Labels (1)
Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

1. It's more of a PowerShell question than a Splunk one.

2. For simple file monitoring it's easier to use UF (or other solutions capable of writing to a HEC endpoint if you find UF "too big" or "too closed source").

3. You haven't even told us at which point this error is raised.

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...