<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Forwarder logs to Splunk Indexer in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-logs-to-Splunk-Indexer/m-p/98537#M20604</link>
    <description>&lt;P&gt;By default, universal and lightweight forwarders are not forwarding the metrics.log, only splunkd.log.&lt;/P&gt;

&lt;P&gt;You can bypass this and force the metrics.log to be forwarded with an inputs.conf like&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor://$SPLUNK_HOME/var/log/splunk/metrics.log]
index=_internal
_TCP_ROUTING = *
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Thu, 25 Sep 2014 23:10:44 GMT</pubDate>
    <dc:creator>yannK</dc:creator>
    <dc:date>2014-09-25T23:10:44Z</dc:date>
    <item>
      <title>Splunk Forwarder logs to Splunk Indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-logs-to-Splunk-Indexer/m-p/98535#M20602</link>
      <description>&lt;P&gt;Do SplunkForwarder forward the metrics.log to the Splunk indexer automatically? I can see the splunkd.log files but not metrics.log file&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2013 20:58:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-logs-to-Splunk-Indexer/m-p/98535#M20602</guid>
      <dc:creator>ssankeneni</dc:creator>
      <dc:date>2013-04-17T20:58:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder logs to Splunk Indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-logs-to-Splunk-Indexer/m-p/98536#M20603</link>
      <description>&lt;P&gt;No, the metrics.log isn't forwarded automatically. Only the splunkd.log receives a special exception. If you look at the documentation for inputs.conf &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/admin/Inputsconf"&gt;here&lt;/A&gt;, it says explicitly:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;&lt;BR /&gt;
* To forward data from the "_internal" index, _TCP_ROUTING must explicitly be set to either "*" &lt;BR /&gt;
or a specific splunktcp target group.&lt;BR /&gt;
&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;The splunkd.log has this setting, but the general directory $SPLUNK_HOME/var/log/splunk does not. You'll have to create a local inputs.conf (in a small config app, or in system/local) containing:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;&lt;BR /&gt;
[monitor://$SPLUNK_HOME/var/log/splunk]&lt;BR /&gt;
_TCP_ROUTING = *&lt;BR /&gt;
&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Once this is in place, restart your forwarder.&lt;/P&gt;</description>
      <pubDate>Fri, 23 May 2014 19:08:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-logs-to-Splunk-Indexer/m-p/98536#M20603</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2014-05-23T19:08:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder logs to Splunk Indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-logs-to-Splunk-Indexer/m-p/98537#M20604</link>
      <description>&lt;P&gt;By default, universal and lightweight forwarders are not forwarding the metrics.log, only splunkd.log.&lt;/P&gt;

&lt;P&gt;You can bypass this and force the metrics.log to be forwarded with an inputs.conf like&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor://$SPLUNK_HOME/var/log/splunk/metrics.log]
index=_internal
_TCP_ROUTING = *
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 25 Sep 2014 23:10:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-logs-to-Splunk-Indexer/m-p/98537#M20604</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2014-09-25T23:10:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder logs to Splunk Indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-logs-to-Splunk-Indexer/m-p/98538#M20605</link>
      <description>&lt;P&gt;This must have been updated with 6.2.1/6.2.2,  I now see the following entry by default in "etc\apps\SplunkUniversalForwarder\default"&lt;/P&gt;

&lt;P&gt;[monitor://$SPLUNK_HOME\var\log\splunk\metrics.log]&lt;BR /&gt;
_TCP_ROUTING = *&lt;BR /&gt;
index = _internal&lt;/P&gt;

&lt;P&gt;So both splunkd.log and metrics.log are now being forwarded to _internal&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:44:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-logs-to-Splunk-Indexer/m-p/98538#M20605</guid>
      <dc:creator>sbrice36</dc:creator>
      <dc:date>2020-09-28T19:44:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder logs to Splunk Indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-logs-to-Splunk-Indexer/m-p/98539#M20606</link>
      <description>&lt;P&gt;I see that in the forwarder app but I also see this in etc/system/default/input.conf which appears to be sending not only the .log files but also the rolled over log files such as .log.1, .log.2, etc.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor://$SPLUNK_HOME\var\log\splunk]
index = _internal
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 28 Dec 2018 19:10:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-logs-to-Splunk-Indexer/m-p/98539#M20606</guid>
      <dc:creator>dstuder</dc:creator>
      <dc:date>2018-12-28T19:10:35Z</dc:date>
    </item>
  </channel>
</rss>

