Splunk Enterprise

How to ask Splunk to get/retrieve a log file?

splunkbee
New Member

Hi,

My log files are stored an a machine. There is no way I can tell this machine to send them somewhere. I must manually go into some directories and pull them all out.
Can Splunk do that for me?

Thanks

0 Karma

woodcock
Esteemed Legend

When you do a "pull" for data instead of a "push", you have to write some glue. You need a Universal Forwarder as a way-station and then you write a script to go to the source machine and pull the data to the UF. You then use traditional means to forward from there, being careful to use the original host for field host (instead of the UF's value).

0 Karma
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...