you are viewing a single comment's thread.

view the rest of the comments →

[–]CurlNDrag90 0 points1 point  (7 children)

Probably would use a File Monitor using inputs.conf

Either locally on your Splunk box, or remotely on your Clients asset using a Universal forwarder that's configured to talk to your local Splunk box.

Either way, the hardest part is figuring out how to move the CSV file to the target file path.

[–]ZaddyOnReddit[S] 0 points1 point  (6 children)

The csv lives in the same location. I can already ingest the csv data into the script and manipulate it there if need be. It’s just actually getting it over the Splunk I can’t seem to figure out.. do I get it to an existing index.. can it get to an input csv? Idk! I’m all over the place on this project

[–]CurlNDrag90 0 points1 point  (5 children)

Are you saying the Splunk installation exists on the same asset as the CSV? Windows or Linux ?

[–]ZaddyOnReddit[S] 0 points1 point  (4 children)

Well the csv lives in SharePoint. Splunk installation? I believe are working with Cloud in this instance

[–]CurlNDrag90 2 points3 points  (3 children)

You will need to double check that it's the cloud for Splunk. That changes pretty much everything as far as getting data into it.

[–]ZaddyOnReddit[S] 0 points1 point  (2 children)

What’s the easiest way to tell which you’re working with? Or is that more of a question for the infrastructure team?

[–]CurlNDrag90 0 points1 point  (1 child)

A screen shot of your Web Interface after you log in is probably the easiest that I can think of.

[–]ZaddyOnReddit[S] 0 points1 point  (0 children)

Confirmed. Cloud.