<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal forwarder - configuration in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Universal-forwarder-configuration/m-p/530368#M4227</link>
    <description>&lt;P&gt;appreciate the quick response, but that video and blog did not tell me which file to view those settings at. My universal forwarders are already forwarding to an index and I'm simply trying to find which file I can CAT to view the indexer.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 23 Nov 2020 05:19:23 GMT</pubDate>
    <dc:creator>verifi81</dc:creator>
    <dc:date>2020-11-23T05:19:23Z</dc:date>
    <item>
      <title>Universal forwarder - configuration</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Universal-forwarder-configuration/m-p/530352#M4225</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;On a Universal Forwarder can someone tell me where the config is that tells the universal forwarder where to send the logs?&lt;/P&gt;&lt;P&gt;I need this for Windows and Linux.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 23 Nov 2020 00:33:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Universal-forwarder-configuration/m-p/530352#M4225</guid>
      <dc:creator>verifi81</dc:creator>
      <dc:date>2020-11-23T00:33:09Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder - configuration</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Universal-forwarder-configuration/m-p/530365#M4226</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222747"&gt;@verifi81&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can check out this video&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.splunk.com/en_us/resources/videos/splunk-education-getting-data-in-with-forwarders.html" target="_blank"&gt;https://www.splunk.com/en_us/resources/videos/splunk-education-getting-data-in-with-forwarders.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;And blog too&lt;/P&gt;&lt;P&gt;&lt;A href="https://geek-university.com/splunk/configure-a-splunk-forwarder-on-linux/" target="_blank"&gt;https://geek-university.com/splunk/configure-a-splunk-forwarder-on-linux/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;-------------------------------------&lt;/P&gt;&lt;P&gt;If this help your like will be appreciated &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Nov 2020 04:33:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Universal-forwarder-configuration/m-p/530365#M4226</guid>
      <dc:creator>vikramyadav</dc:creator>
      <dc:date>2020-11-23T04:33:30Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder - configuration</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Universal-forwarder-configuration/m-p/530368#M4227</link>
      <description>&lt;P&gt;appreciate the quick response, but that video and blog did not tell me which file to view those settings at. My universal forwarders are already forwarding to an index and I'm simply trying to find which file I can CAT to view the indexer.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Nov 2020 05:19:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Universal-forwarder-configuration/m-p/530368#M4227</guid>
      <dc:creator>verifi81</dc:creator>
      <dc:date>2020-11-23T05:19:23Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder - configuration</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Universal-forwarder-configuration/m-p/530369#M4228</link>
      <description>&lt;P&gt;I found it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's under&amp;nbsp;&lt;SPAN&gt;$SPLUNK_HOME/etc/apps/search/local/&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The file is outputs.conf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Nov 2020 05:29:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Universal-forwarder-configuration/m-p/530369#M4228</guid>
      <dc:creator>verifi81</dc:creator>
      <dc:date>2020-11-23T05:29:17Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder - configuration</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Universal-forwarder-configuration/m-p/530371#M4229</link>
      <description>&lt;P&gt;I'm not sure which log file you are interested in so you can use btool to check outputs.conf&lt;/P&gt;&lt;P&gt;For Linux and Linux&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;$&lt;/STRONG&gt;&lt;EM&gt;&lt;STRONG&gt;Splunk_Home/splunk btool outputs list --debug&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-------------------------------------&lt;/P&gt;&lt;P&gt;If this help your like will be appreciated &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Nov 2020 05:40:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Universal-forwarder-configuration/m-p/530371#M4229</guid>
      <dc:creator>vikramyadav</dc:creator>
      <dc:date>2020-11-23T05:40:52Z</dc:date>
    </item>
  </channel>
</rss>

