Step 3: Data Collection
One quick note — we use a Splunk term, “$SPLUNK_HOME”, to denote the base install path of Splunk or the Splunk forwarder. On a Windows server, this is usually c:\program files\splunk or c:\program files\splunkuniversalforwarder. On Linux it’s usually /opt/splunk or /opt/splunkforwarder.
Prepare the host which UCM will SFTP to
Next, we recommend the following steps, where you’ll set up a small separate host that will receive the files from CUCM via SFTP, and will forward them onto your Splunk instance via the Splunk Universal Forwarder. However, on-premise folks (e.g. ones not in cloud) with only a single Splunk instance should know that it’s a fine option to simply SFTP the files directly to the main Splunk host.