Splunk Enterprise

Importing logs from offline linux server

AbuRipleigh
New Member

Hi all,

 

Can anyone direct me to a post or documentation on the best procedure for importing logs copied off a non-networked linux server? We're looking at copying the log files to a network share and then importing, but we've never done this for a Linux box that doesn't have a forwarder.

 

cheers.

Labels (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Probably the easiest way is create a mount point / share (e.g. /srv/logs/<node>/ no matter where and how it's named, do just like your organization naming standards said), and under that you could put those in one or several sub directories. Probably you could/should use day/month/year etc. sub directories there. It depends how and how often you are copied those logs there. Then use just your normal UF's inputs.conf which as modified by path part to point correct logs under that mount point.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...