Splunk Enterprise

How to collect different types of log data from different applications, residing in a single server?

raj_mpl
Path Finder

How to collect the different types of logs form different types of applications? All the applications were residing in a single server
with a single universal forwarder or do we need to configure anything.

Tags (1)
0 Karma
1 Solution

FrankVl
Ultra Champion

Without more specific info on how those applications write/send their logs, it is a bit hard to give any specific answer.

But basically I would say you can for instance create a separate inputs.conf stanza for each application, pointing it to the relevant log directory and setting individual index and sourcetype settings as desired.

View solution in original post

0 Karma

FrankVl
Ultra Champion

Without more specific info on how those applications write/send their logs, it is a bit hard to give any specific answer.

But basically I would say you can for instance create a separate inputs.conf stanza for each application, pointing it to the relevant log directory and setting individual index and sourcetype settings as desired.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...