On machines that run Windows Vista or Windows Server 2008 and higher, you can use the MonitorNoHandle input to monitor files that Windows rotates automatically. However, you might want to use the upload input to monitor a file such as an archive of historical data, only one time. You can use the monitor input to add nearly all your data sources from files and directories. You can also use a universal or heavy forwarder, as you would with Splunk Cloud Platform. If you have Splunk Enterprise, you can monitor files using the CLI, Splunk Web, or the nf configuration file directly on your Splunk Enterprise instance. You can upload a single file at a time to Splunk Cloud Platform using Splunk Web. While you must use a forwarder for monitor and MonitorNoHandle input processors, you do not need to use a forwarder to upload a single file. You need read access to the file or directory to monitor it.įorwarders have three file input processors: You perform the data collection on the forwarder and then send the data to the Splunk Cloud Platform instance. To monitor files and directories in Splunk Cloud Platform, you must use a universal or a heavy forwarder in nearly all cases.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |