Splunk Enterprise

Importing logs from offline linux server

AbuRipleigh
New Member

Hi all,

 

Can anyone direct me to a post or documentation on the best procedure for importing logs copied off a non-networked linux server? We're looking at copying the log files to a network share and then importing, but we've never done this for a Linux box that doesn't have a forwarder.

 

cheers.

Labels (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Probably the easiest way is create a mount point / share (e.g. /srv/logs/<node>/ no matter where and how it's named, do just like your organization naming standards said), and under that you could put those in one or several sub directories. Probably you could/should use day/month/year etc. sub directories there. It depends how and how often you are copied those logs there. Then use just your normal UF's inputs.conf which as modified by path part to point correct logs under that mount point.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...