Quantcast
Channel: Latest Questions on Splunk Answers
Viewing all articles
Browse latest Browse all 13053

Unknown source sending logs

$
0
0

Hi,

I am in a weird situation. I have recently joined a new company. The guy who setup splunk left the company after upgrading the splunk and the PCI app "Splunk App for PCI Compliance" to latest version. After upgrade we are getting logs from various sources which I am not sure if they are genuine or not. I only have access to the splunk server but not the clients. I have previous knowledge of splunk setup.

When I check the logs in splunk the source is something like this source=/opt/splunk/var/spool/splunk/singlehost.sample.sav hostname="splunk server", and sourcetype="sav".

Now I logged into the server console through putty to see the original logs in /opt/splunk/var/spool/splunk/ but I cant find any. Could someone suggest me how to troubleshoot this issue or if anyone else faced this issue please help me.

Regards, Harish


Viewing all articles
Browse latest Browse all 13053

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>