OK my ProxySGs are saving logs in this format: SG_%f_%c_%l%m%d%H%M%S.log in FTP server. I can access them using a FTP client by ftp://
[email protected]/BlueCoat, but not sure what to put in the first line of the inputs.conf file indicated here:
[monitor://<log path>]
I put the following but no luck:
[monitor:///10.1.1.1/BlueCoat]
How the Splunk is supposed to authenticate with the FTP server? Where do I indicate that?
Or it doesn't work this way and a forwarder on the FTP server needs to be setup to send the logs to Splunk?
... View more