Splunk can collect data from many sources. File & directory monitoring watches log files for new data. Network inputs listen on TCP/UDP ports for incoming data streams.
Scripted inputs run scripts at intervals and index their output. The HTTP Event Collector (HEC) accepts data over HTTP/HTTPS — ideal for applications and cloud services.
Each input type is configured through inputs.conf or through Splunk Web under Settings > Data Inputs.
[monitor:///var/log/syslog]
disabled = false
index = os_logs
sourcetype = syslog