Splunk Enterprise

How to ask Splunk to get/retrieve a log file?

splunkbee
New Member

Hi,

My log files are stored an a machine. There is no way I can tell this machine to send them somewhere. I must manually go into some directories and pull them all out.
Can Splunk do that for me?

Thanks

0 Karma

woodcock
Esteemed Legend

When you do a "pull" for data instead of a "push", you have to write some glue. You need a Universal Forwarder as a way-station and then you write a script to go to the source machine and pull the data to the UF. You then use traditional means to forward from there, being careful to use the original host for field host (instead of the UF's value).

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...