<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal Forwarder best setting in Linux in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-best-setting-in-Linux/m-p/700467#M28660</link>
    <description>I agree with &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt; that this is quite probably ok. It’s totally dependent on your data.</description>
    <pubDate>Sun, 29 Sep 2024 08:09:42 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2024-09-29T08:09:42Z</dc:date>
    <item>
      <title>Universal Forwarder best setting in Linux</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-best-setting-in-Linux/m-p/699777#M28621</link>
      <description>&lt;P&gt;Yesterday i was ingest new server in my Splunk&lt;/P&gt;&lt;P&gt;in my case, in directory&amp;nbsp;/opt/splunkforwarder/etc/system/local/inputs.conf&amp;nbsp; im use setting like this&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;[monitor:///var/log/]
disabled = false
index = &amp;lt;NewIndex&amp;gt;

[monitor:///home/*/.bash_history]
disabled = false
index = &amp;lt;NewIndex&amp;gt;
sourcetype = bash_history&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;I ingest 6 Server Ubuntu, in the first 4hour i got too much data like 1GB (got shocked cause it only 4hours) but after 2 Days it only get 4.88GB.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What i understand is maybe in the first 4hour it read all old data cache fom .bash_history and /var/log (maybe) because when i check it in Indexer it says&amp;nbsp;Earliest Event = 15 years ago&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zksvc_0-1727061862786.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32738iABB8362DE771DE74/image-size/medium?v=v2&amp;amp;px=400" role="button" title="zksvc_0-1727061862786.png" alt="zksvc_0-1727061862786.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Question is, it is normal or need to change in my&amp;nbsp;inputs.conf ?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;~Danke&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 03:25:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-best-setting-in-Linux/m-p/699777#M28621</guid>
      <dc:creator>zksvc</dc:creator>
      <dc:date>2024-09-23T03:25:53Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder best setting in Linux</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-best-setting-in-Linux/m-p/699782#M28622</link>
      <description>&lt;P&gt;Yes, it is perfectly normal. By default splunk reads all it can from the specified input file(s) and then keeps track of how much it has already read and only reads newly written entries. Nothing to worry about.&lt;/P&gt;&lt;P&gt;I have two issues with your inputs. One is that monitoring .bash_history alone makes relatively little sense (things you want to find are usually pretty easy to avoid being written to bash histiry).&lt;/P&gt;&lt;P&gt;Anotheris that ingesting all /var/log with single sourcetype will end with a horrible mess since you have many different kinds of logs there.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 05:11:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-best-setting-in-Linux/m-p/699782#M28622</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-09-23T05:11:38Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder best setting in Linux</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-best-setting-in-Linux/m-p/699794#M28623</link>
      <description>&lt;P&gt;Thankyou for your information, reason why i create /var/log because i want ingest everything in /log and Splunk do it perfectly.&amp;nbsp; It will be named default by Splunk but its okay&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zksvc_0-1727073621038.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32739iF7D8ECBAFE70FA35/image-size/medium?v=v2&amp;amp;px=400" role="button" title="zksvc_0-1727073621038.png" alt="zksvc_0-1727073621038.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;And for .bash_history i input that because that's a request.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once again thanks sir, now i no need worries anymore about this newIndex size.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 06:42:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-best-setting-in-Linux/m-p/699794#M28623</guid>
      <dc:creator>zksvc</dc:creator>
      <dc:date>2024-09-23T06:42:10Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder best setting in Linux</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-best-setting-in-Linux/m-p/699803#M28624</link>
      <description>&lt;P&gt;Yes, but in /var/log there are many different kinds of files (and typically even many different kinds of events within some files) and each of them should be parsed differently. If you just ingest all of them into one big "sack", you will most definitely lose at least some info (like properly parsed timestamps on some events) and you will not have properly parsed fields for many of those events.&lt;/P&gt;&lt;P&gt;So if you have - for example - /var/log/exim/main.log you should ingest it separately with exim_main sourcetyp (and reject.log should have own input stanza with exim_reject sourcetype). Apache httpd access logs should be ingested separately with one of the access_* sourcetypes depending on your apache configuration.&lt;/P&gt;&lt;P&gt;And so on.&lt;/P&gt;&lt;P&gt;If you just pull everything with one generic sourcetype... well, you can do a full-text search but not much more. You're losing a lot of functionality.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 08:51:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-best-setting-in-Linux/m-p/699803#M28624</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-09-23T08:51:51Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder best setting in Linux</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-best-setting-in-Linux/m-p/699805#M28625</link>
      <description>&lt;P&gt;Thankyou for your information, maybe i will checking it in latest Sourcetype generate default by splunk yesterday. So i can validating directory paths for inputs.conf&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 09:04:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-best-setting-in-Linux/m-p/699805#M28625</guid>
      <dc:creator>zksvc</dc:creator>
      <dc:date>2024-09-23T09:04:43Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder best setting in Linux</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-best-setting-in-Linux/m-p/699899#M28633</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;As your information Yesterday if my inputs.conf will mess the sourcetype so i was assesment all sourcetype was generated in my searchhead.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you please correction my inputs.conf ? here&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor:///var/log/audit/audit.log]
disabled = false
index = NewIndex
sourcetype = linux_audit

[monitor:///var/log/auth.log]
disabled = false
index = NewIndex
sourcetype = auth-too_small

[monitor:///var/log/cron]
disabled = false
index = NewIndex
sourcetype = kern-too_small

[monitor:///var/log/kern.log]
disabled = false
index = NewIndex
sourcetype = kern-too_small

[monitor:///var/log/messages]
disabled = false
index = NewIndex
sourcetype = syslog

[monitor:///var/log/mongodb/mongod.log]
disabled = false
index = NewIndex
sourcetype = mongod-2

[monitor:///var/log/nginx/access.log]
disabled = false
index = NewIndex
sourcetype = access_combined

[monitor:///var/log/nginx/error-NewIndex-fe.log]
disabled = false
index = NewIndex
sourcetype = error-NewIndex-fe-too_small

[monitor:///var/log/nginx/jm-click-fe.log]
disabled = false
index = NewIndex
sourcetype = jm-click-fe-too_small

[monitor:///var/log/nginx/NewIndex-ess-http-3001.log]
disabled = false
index = NewIndex
sourcetype = NewIndex-ess-http-too_small

[monitor:///var/log/nginx/NewIndex-ess-pakta-http.log.1]
disabled = false
index = NewIndex
sourcetype = NewIndex-ess-http-too_small

[monitor:///var/log/nginx/NewIndex-jmpd-http.log]
disabled = false
index = NewIndex
sourcetype = access_combined

[monitor:///var/log/nginx/NewIndex-be.log]
disabled = false
index = NewIndex
sourcetype = access_combined

[monitor:///var/log/nginx/NewIndex-cms-be.log]
disabled = false
index = NewIndex
sourcetype = NewIndex-cms-be-too_small

[monitor:///var/log/redis/redis-server.log]
disabled = false
index = NewIndex
sourcetype = redis-server-too_small

[monitor:///var/log/sssd/sssd_NewIndex.co.id.log]
disabled = false
index = NewIndex
sourcetype = sssd_NewIndex.co.id-too_small

[monitor:///var/log/syslog]
disabled = false
index = NewIndex
sourcetype = syslog

[monitor:///var/log/ubuntu-advantage-timer.log]
disabled = false
index = NewIndex
sourcetype = ubuntu-advantage-timer.log-3

[monitor:///var/log/ubuntu-advantage.log]
disabled = false
index = NewIndex
sourcetype = ubuntu-advantage-6

[monitor:///var/log/ufw.log]
disabled = false
index = NewIndex
sourcetype = syslog

[monitor:///var/log/unattended-upgrades/unattended-upgrades.log]
disabled = false
index = NewIndex
sourcetype = unattended-upgrades

[monitor:///var/log/vmware-vmtoolsd-root.log]
disabled = false
index = NewIndex
sourcetype = vmware-vmtoolsd-root

[monitor:///home/*/.bash_history]
disabled = false
index = NewIndex
sourcetype = bash_history&lt;/LI-CODE&gt;&lt;P&gt;Or maybe you have best practice setting for my case ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2024 01:10:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-best-setting-in-Linux/m-p/699899#M28633</guid>
      <dc:creator>zksvc</dc:creator>
      <dc:date>2024-09-24T01:10:50Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder best setting in Linux</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-best-setting-in-Linux/m-p/700437#M28653</link>
      <description>Hi&lt;BR /&gt;&lt;BR /&gt;Have you look e.g Splunk Add-on for Unix and Linux &lt;A href="https://splunkbase.splunk.com/app/833" target="_blank"&gt;https://splunkbase.splunk.com/app/833&lt;/A&gt; to ingest those logs into Splunk? Usually it's best to use some TA as those do lot of need stuff like make inputs as a CIM complaint &lt;A href="https://splunkbase.splunk.com/app/1621" target="_blank"&gt;https://splunkbase.splunk.com/app/1621&lt;/A&gt; Then you can easily use e.g. InfoSec app &lt;A href="https://splunkbase.splunk.com/app/4240" target="_blank"&gt;https://splunkbase.splunk.com/app/4240&lt;/A&gt; to monitor what is happening in your environment.&lt;BR /&gt;&lt;BR /&gt;Those which has suffix -too_small is somenthing which haven't any sourcetype definitions on splunk side. Splunk just generate that name for those. You should do a real data onboarding for those files/sources.&lt;BR /&gt;&lt;BR /&gt;One other thing what you should check and change if needed. You should never run UF on those nodes as root. Use some other user like splunk or splunkfwd. Then your issue is that those user haven't access to all those logs and that you also needs to fix.&lt;BR /&gt;&lt;BR /&gt;r. Ismo</description>
      <pubDate>Sat, 28 Sep 2024 15:54:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-best-setting-in-Linux/m-p/700437#M28653</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-09-28T15:54:48Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder best setting in Linux</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-best-setting-in-Linux/m-p/700462#M28656</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your information, after i check it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;-&amp;nbsp;Splunk Add-on for Unix and Linux [Installed]&lt;/P&gt;&lt;P&gt;- Splunk Common Information Model (CIM) [Installed]&lt;/P&gt;&lt;P&gt;-&amp;nbsp;InfoSec App for Splunk [Not Installed]&lt;/P&gt;&lt;P&gt;For the UF issue there is no problem at all, here I can get all the logs I need. It's just that the data I get has messy fields like this picture&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zksvc_0-1727581957271.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32865i41AE1CAE7178F778/image-size/medium?v=v2&amp;amp;px=400" role="button" title="zksvc_0-1727581957271.png" alt="zksvc_0-1727581957271.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I think it's not okay that's why i create topic for asking this problem&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Sep 2024 03:53:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-best-setting-in-Linux/m-p/700462#M28656</guid>
      <dc:creator>zksvc</dc:creator>
      <dc:date>2024-09-29T03:53:51Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder best setting in Linux</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-best-setting-in-Linux/m-p/700464#M28658</link>
      <description>&lt;P&gt;This actually looks OK-ish. You probably have some json data which gets parsed into those "multilevel" fields.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Sep 2024 05:25:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-best-setting-in-Linux/m-p/700464#M28658</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-09-29T05:25:17Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder best setting in Linux</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-best-setting-in-Linux/m-p/700467#M28660</link>
      <description>I agree with &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt; that this is quite probably ok. It’s totally dependent on your data.</description>
      <pubDate>Sun, 29 Sep 2024 08:09:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-best-setting-in-Linux/m-p/700467#M28660</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-09-29T08:09:42Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder best setting in Linux</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-best-setting-in-Linux/m-p/700471#M28664</link>
      <description>&lt;P&gt;Oke Thankyou&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;atleast in splunk can ingest everything. If want get specify data Analyst can regex it&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Sep 2024 08:45:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Universal-Forwarder-best-setting-in-Linux/m-p/700471#M28664</guid>
      <dc:creator>zksvc</dc:creator>
      <dc:date>2024-09-29T08:45:59Z</dc:date>
    </item>
  </channel>
</rss>

