<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Universal Forwarder - Add another Log FIle to Index in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Add-another-Log-FIle-to-Index/m-p/96705#M20147</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;I have a Linux Splunk Indexer.&lt;/P&gt;

&lt;P&gt;How do I add another log file to be indexed by Splunk to the Universal Forwarder on a Windows Server ?&lt;/P&gt;

&lt;P&gt;Many Thanks&lt;/P&gt;

&lt;P&gt;Regards &lt;BR /&gt;
Peta Gergen&lt;BR /&gt;
&lt;A href="mailto:peta.gergen@team.telstra.com"&gt;peta.gergen@team.telstra.com&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 24 Oct 2011 05:18:24 GMT</pubDate>
    <dc:creator>pgergen</dc:creator>
    <dc:date>2011-10-24T05:18:24Z</dc:date>
    <item>
      <title>Universal Forwarder - Add another Log FIle to Index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Add-another-Log-FIle-to-Index/m-p/96705#M20147</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;I have a Linux Splunk Indexer.&lt;/P&gt;

&lt;P&gt;How do I add another log file to be indexed by Splunk to the Universal Forwarder on a Windows Server ?&lt;/P&gt;

&lt;P&gt;Many Thanks&lt;/P&gt;

&lt;P&gt;Regards &lt;BR /&gt;
Peta Gergen&lt;BR /&gt;
&lt;A href="mailto:peta.gergen@team.telstra.com"&gt;peta.gergen@team.telstra.com&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2011 05:18:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Add-another-Log-FIle-to-Index/m-p/96705#M20147</guid>
      <dc:creator>pgergen</dc:creator>
      <dc:date>2011-10-24T05:18:24Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder - Add another Log FIle to Index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Add-another-Log-FIle-to-Index/m-p/96706#M20148</link>
      <description>&lt;P&gt;There's a whole manual covering these topics in the docs. This should be a good place to start: &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/Configureyourinputs"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Data/Configureyourinputs&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Long story short: either use the CLI or add a directive in in an &lt;CODE&gt;inputs.conf&lt;/CODE&gt; file (for instance in &lt;CODE&gt;$SPLUNK_HOME/etc/system/local&lt;/CODE&gt;).&lt;/P&gt;

&lt;P&gt;CLI: &lt;CODE&gt;$SPLUNK_HOME/bin/splunk add monitor &amp;lt;logdir&amp;gt;&lt;/CODE&gt;&lt;BR /&gt;&lt;BR /&gt;
&lt;CODE&gt;inputs.conf&lt;/CODE&gt;: &lt;CODE&gt;[monitor:///&amp;lt;logdir&amp;gt;]&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2011 06:54:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Add-another-Log-FIle-to-Index/m-p/96706#M20148</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2011-10-24T06:54:34Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder - Add another Log FIle to Index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Add-another-Log-FIle-to-Index/m-p/96707#M20149</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;

&lt;P&gt;I have similar problem!!!&lt;/P&gt;

&lt;P&gt;I have two instances one is splunk-server and other is splunk-forwarder(universalForwarder).&lt;BR /&gt;
Everything is fine with configuration ,then I tried  to monitor tomcat logs and I have perform below steps on &lt;EM&gt;forwarder&lt;/EM&gt;.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;/usr/share/splunk_setup/splunkforwarder/bin/splunk add monitor /usr/share/apache-tomcat-7.0.42/logs/catalina.out -index default -sourcetype log4j -hostname splunkforwarder&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;But in search tab of splunk-web I always get &lt;STRONG&gt;&lt;EM&gt;No results found.&lt;/EM&gt;&lt;/STRONG&gt; &lt;/P&gt;

&lt;P&gt;Am I missing something !!!.Please help me out.&lt;BR /&gt;
Thanks in advance!!&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2013 14:49:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Add-another-Log-FIle-to-Index/m-p/96707#M20149</guid>
      <dc:creator>lalit_mohan</dc:creator>
      <dc:date>2013-11-13T14:49:15Z</dc:date>
    </item>
  </channel>
</rss>

