如何使用 splunk 监控 GitHub Appliance 实例

how to monitor the GitHub Appliance instance using splunk

我们有 GitHub 企业设备,我们需要将 GitHub 日志转发到 splunk 可以监控的独立存储。我们如何实现这一点

您将需要启用日志转发,它通过 syslog

从 GitHub 设备导出审核日志

https://help.github.com/en/enterprise/2.16/admin/installation/log-forwarding

On the Management Console settings page, in the left sidebar, click Monitoring.
Select Enable log forwarding.
In the Server address field, type the address of the server to which you want to forward logs. You can specify multiple addresses in a comma-separated list.
In the Protocol drop-down menu, select the protocol to use to communicate with the log server. The protocol will apply to all specified log destinations.

您将需要在 Splunk 端启用接收器以接收系统日志,或者从系统日志侦听器写入的文件中读取它