Getting Data In

How to parse windows server logs with .conf file as well as with rex?

Mayuresh1516
New Member

I am using a windows server which is configured with forwarder.
Now I need all those logs on my desktop from where I want to monitor these logs.
Through indexers I will be passing those logs.
Please help me out for parsing such logs.
(Note: Latest version of windows server is being used)

0 Karma

woodcock
Esteemed Legend

Where is the forwarder configured to send the data (outputs.conf)?
You don't ever "need all those logs on your desktop"; they will go into an indexer which will do your bidding when you access it's data through your browser ("on your desktop").
The indexer will not "pass the logs"; the indexer is the final destination for them.
As far as "parsing", I assume you already have a "rex" command working so you can convert this to an automatic field extraction with props.conf:
http://docs.splunk.com/Documentation/Splunk/latest/admin/Propsconf

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...