<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal Forwarder for OSX installed - how is it configured ? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-for-OSX-installed-how-is-it-configured/m-p/72596#M14810</link>
    <description>&lt;P&gt;You need to create the following files:&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;inputs.conf&lt;/STRONG&gt; - to identify the files to be monitored&lt;BR /&gt;&lt;BR /&gt;
See &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/Editinputs.conf"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Data/Editinputs.conf&lt;/A&gt; for help. You may also need props.conf, but it depends on your inputs. Here is an example that monitors a single syslog log file:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///logs/mylogfile.log]
sourcetype=syslog
host=yourOSXhostname
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;outputs.conf&lt;/STRONG&gt; - to tell Splunk where to forward the data. Example:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout:my_indexer]
server=10.10.10.1:9997
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Note that you have to supply the server ip (or dns name) and the port number where Splunk is listening for forwarded data. See &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Configureforwarderswithoutputs.confd"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Configureforwarderswithoutputs.confd&lt;/A&gt; for more info and options.&lt;/P&gt;

&lt;P&gt;Put the files in "/Applications/splunkforwarder/etc/system/local" or your equivalent.&lt;/P&gt;</description>
    <pubDate>Fri, 15 Jun 2012 19:17:05 GMT</pubDate>
    <dc:creator>lguinn2</dc:creator>
    <dc:date>2012-06-15T19:17:05Z</dc:date>
    <item>
      <title>Universal Forwarder for OSX installed - how is it configured ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-for-OSX-installed-how-is-it-configured/m-p/72595#M14809</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;

&lt;P&gt;I have the OSX Universal Forwarder installed on a 10.5 machine and Splunk installed on a server successfully receiving events from two Windows machines.&lt;/P&gt;

&lt;P&gt;How do I configure the OSX Forwarder to:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Nominate the log files I want
monitored.&lt;/LI&gt;
&lt;LI&gt;Set the IP address of the server that the Forwarder will send event data too.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;I cannot find this specific information in the documentation.&lt;/P&gt;

&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2012 22:54:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-for-OSX-installed-how-is-it-configured/m-p/72595#M14809</guid>
      <dc:creator>eyeLikeCarrots</dc:creator>
      <dc:date>2012-06-11T22:54:46Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder for OSX installed - how is it configured ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-for-OSX-installed-how-is-it-configured/m-p/72596#M14810</link>
      <description>&lt;P&gt;You need to create the following files:&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;inputs.conf&lt;/STRONG&gt; - to identify the files to be monitored&lt;BR /&gt;&lt;BR /&gt;
See &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/Editinputs.conf"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Data/Editinputs.conf&lt;/A&gt; for help. You may also need props.conf, but it depends on your inputs. Here is an example that monitors a single syslog log file:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///logs/mylogfile.log]
sourcetype=syslog
host=yourOSXhostname
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;outputs.conf&lt;/STRONG&gt; - to tell Splunk where to forward the data. Example:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout:my_indexer]
server=10.10.10.1:9997
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Note that you have to supply the server ip (or dns name) and the port number where Splunk is listening for forwarded data. See &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Configureforwarderswithoutputs.confd"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Configureforwarderswithoutputs.confd&lt;/A&gt; for more info and options.&lt;/P&gt;

&lt;P&gt;Put the files in "/Applications/splunkforwarder/etc/system/local" or your equivalent.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jun 2012 19:17:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-for-OSX-installed-how-is-it-configured/m-p/72596#M14810</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2012-06-15T19:17:05Z</dc:date>
    </item>
  </channel>
</rss>

