Monitoring Splunk

Inserting mac os event logs in splunk

pulen
New Member

I am really struggling to add my macos data into splunk just like how we can upload the event logs of windows. is there any add-ons that i can install to help me do this? if there is, can anyone explain how to configure it and make it work? 

Labels (1)
0 Karma

deepakc
Builder

To get you started here's a number of links for you read and work through

In short you need the nix TA, UF and configure inputs and outputs based on your requirements.

#This shows you the TA Required (Nix TA)
https://splunkbase.splunk.com/app/833


#This shows you the OS Supported = MacOs is listed
https://docs.splunk.com/Documentation/AddOns/latest/UnixLinux/About

 

#Read the release notes
https://docs.splunk.com/Documentation/AddOns/released/UnixLinux/Releasenotes

And you will need to install a Universal Forwarder for the MacOS + configure outputs and TA inputs
https://www.splunk.com/en_us/download/universal-forwarder.html

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...