<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Forwarding and Receiving in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarding-and-Receiving/m-p/99482#M20800</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I would like to monitor my other computer under one log file by using the forwarding and receiving. I've already use the splunk web to configure all my forwarding and receiving. The output I want is when the log file in my laptop is being updated with something new it would also update the log file in my desktop. But somehow, it didn't work out. I hope to solve this as soon as possible so I really need the help from you guys.&lt;/P&gt;

&lt;P&gt;The input.conf has nothing except my host name.&lt;/P&gt;

&lt;P&gt;And my output is this:&lt;/P&gt;

&lt;P&gt;[tcpout]&lt;/P&gt;

&lt;P&gt;defaultGroup = xxx.xx.xxx.xxx_9997&lt;/P&gt;

&lt;P&gt;disabled = false&lt;/P&gt;

&lt;P&gt;indexAndForward = 1&lt;/P&gt;

&lt;P&gt;[tcpout:xxx.xx.xxx.xxx_9997]&lt;/P&gt;

&lt;P&gt;autoLB = true&lt;/P&gt;

&lt;P&gt;server = xxx.xx.xxx.xxx:9997&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Those x is referring to my desktop IP address.&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Wed, 11 May 2011 08:57:48 GMT</pubDate>
    <dc:creator>cassie90</dc:creator>
    <dc:date>2011-05-11T08:57:48Z</dc:date>
    <item>
      <title>Splunk Forwarding and Receiving</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarding-and-Receiving/m-p/99482#M20800</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I would like to monitor my other computer under one log file by using the forwarding and receiving. I've already use the splunk web to configure all my forwarding and receiving. The output I want is when the log file in my laptop is being updated with something new it would also update the log file in my desktop. But somehow, it didn't work out. I hope to solve this as soon as possible so I really need the help from you guys.&lt;/P&gt;

&lt;P&gt;The input.conf has nothing except my host name.&lt;/P&gt;

&lt;P&gt;And my output is this:&lt;/P&gt;

&lt;P&gt;[tcpout]&lt;/P&gt;

&lt;P&gt;defaultGroup = xxx.xx.xxx.xxx_9997&lt;/P&gt;

&lt;P&gt;disabled = false&lt;/P&gt;

&lt;P&gt;indexAndForward = 1&lt;/P&gt;

&lt;P&gt;[tcpout:xxx.xx.xxx.xxx_9997]&lt;/P&gt;

&lt;P&gt;autoLB = true&lt;/P&gt;

&lt;P&gt;server = xxx.xx.xxx.xxx:9997&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Those x is referring to my desktop IP address.&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2011 08:57:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarding-and-Receiving/m-p/99482#M20800</guid>
      <dc:creator>cassie90</dc:creator>
      <dc:date>2011-05-11T08:57:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarding and Receiving</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarding-and-Receiving/m-p/99483#M20801</link>
      <description>&lt;P&gt;I am not sure I understand what your expectation is here. Are you saying that you expect a particular log file to be updated with the same information as another logfile where you have a forwarder installed? If so, Splunk isn't going to do that. &lt;/P&gt;

&lt;P&gt;What Splunk can do is to connect make connections from the forwarder to the indexer and allow you to see when files are being changed. In order to do this, you'd need to set up fschange on the file where you'd like to see changes. Could you elaborate on how your file inputs are configured?&lt;/P&gt;

&lt;P&gt;You'd want to set this up on your forwarder, instructions can be found here:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.splunk.com/base/Documentation/4.2.1/Data/Monitorchangestoyourfilesystem"&gt;http://www.splunk.com/base/Documentation/4.2.1/Data/Monitorchangestoyourfilesystem&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2011 15:16:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarding-and-Receiving/m-p/99483#M20801</guid>
      <dc:creator>jbsplunk</dc:creator>
      <dc:date>2011-05-11T15:16:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarding and Receiving</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarding-and-Receiving/m-p/99484#M20802</link>
      <description>&lt;P&gt;Erm. Is it possible that I could monitor other computers using the forwarder ?&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2011 16:05:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarding-and-Receiving/m-p/99484#M20802</guid>
      <dc:creator>cassie90</dc:creator>
      <dc:date>2011-05-11T16:05:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarding and Receiving</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarding-and-Receiving/m-p/99485#M20803</link>
      <description>&lt;P&gt;One way or another, the forwarder has to be able to see the data you want it to eat. If that is via a mount point or some other shared mechanism that allows the forwarder access to read the files, then the Forwarder will eat that data and send it over to the indexer. &lt;/P&gt;

&lt;P&gt;Keep in mind, Splunk should be able to sustain 800-1000 IOPS. Things like NFS may not function well if you've got a lot of data Splunk needs to ingest. If you are only monitoring a few files, this may not be as much of a concern.&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2011 16:11:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarding-and-Receiving/m-p/99485#M20803</guid>
      <dc:creator>jbsplunk</dc:creator>
      <dc:date>2011-05-11T16:11:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarding and Receiving</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarding-and-Receiving/m-p/99486#M20804</link>
      <description>&lt;P&gt;Erm. What I meant is it possible like Am i able to monitor other computer within one log files. Meaning my log file will monitor both my lappy ip address and desktop ip address. Is it possible if I use it with forwarder.&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2011 16:21:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarding-and-Receiving/m-p/99486#M20804</guid>
      <dc:creator>cassie90</dc:creator>
      <dc:date>2011-05-11T16:21:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarding and Receiving</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarding-and-Receiving/m-p/99487#M20805</link>
      <description>&lt;P&gt;The forwarder can monitor whatever you'd like it to monitor, but the thing is that it can only monitor what it can see. You need some method of getting data from the locations where they were created into the location that the forwarder is monitoring. Otherwise, you'd have to install a forwarder on your laptop and the desktop, then set up a data input to monitor the file.&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2011 16:28:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarding-and-Receiving/m-p/99487#M20805</guid>
      <dc:creator>jbsplunk</dc:creator>
      <dc:date>2011-05-11T16:28:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarding and Receiving</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarding-and-Receiving/m-p/99488#M20806</link>
      <description>&lt;P&gt;Okay ! I will try it out. Thanks for the solution (: I will get back to you if it works. Thanks (:&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2011 16:59:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarding-and-Receiving/m-p/99488#M20806</guid>
      <dc:creator>cassie90</dc:creator>
      <dc:date>2011-05-11T16:59:50Z</dc:date>
    </item>
  </channel>
</rss>

