<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Indexing logs to remote server in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Indexing-logs-to-remote-server/m-p/104420#M21993</link>
    <description>&lt;P&gt;This is a general guideline of where the different conf files should live. If you need more details I suggest you re-read the documentation with this guideline in mind. Good luck.&lt;/P&gt;

&lt;P&gt;inputs.conf needs to be defined on both the forwarders and the indexers.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;On the forwarders it needs to define what you are monitoring and what index to write to&lt;/LI&gt;
&lt;LI&gt;On the indexer it needs to define the port and such that it needs to listen at&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;outputs.conf needs to be defined on the forwarders&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;It needs to define what indexer it will write to&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;props.conf needs to be defined on the indexer&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;It needs to define how to parse the data by sourcetype that it receives&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;indexes.conf needs to be defined on the indexer&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;It needs to define the basic information for where the data should be stored&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Tue, 23 Apr 2013 18:52:53 GMT</pubDate>
    <dc:creator>aholzer</dc:creator>
    <dc:date>2013-04-23T18:52:53Z</dc:date>
    <item>
      <title>Indexing logs to remote server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexing-logs-to-remote-server/m-p/104419#M21992</link>
      <description>&lt;P&gt;I have installed 1 forwarder on my linux machine-1 and another on windows apache machine-2. The splunk has been installed on another windows machine-3. i was able to enable the receiving and am able to view forwader in splunk.&lt;BR /&gt;
Now i need to monitor my apache logs from machine-1 and application logs from machine-2 from the remote machine-3 where splunk is installed. I have read the documentations, but it didnt helped me much.&lt;BR /&gt;
What entry need to be made in outputs.conf on forwader and inputs.conf on splunk for this requirement.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2013 17:50:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexing-logs-to-remote-server/m-p/104419#M21992</guid>
      <dc:creator>eippops</dc:creator>
      <dc:date>2013-04-23T17:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: Indexing logs to remote server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexing-logs-to-remote-server/m-p/104420#M21993</link>
      <description>&lt;P&gt;This is a general guideline of where the different conf files should live. If you need more details I suggest you re-read the documentation with this guideline in mind. Good luck.&lt;/P&gt;

&lt;P&gt;inputs.conf needs to be defined on both the forwarders and the indexers.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;On the forwarders it needs to define what you are monitoring and what index to write to&lt;/LI&gt;
&lt;LI&gt;On the indexer it needs to define the port and such that it needs to listen at&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;outputs.conf needs to be defined on the forwarders&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;It needs to define what indexer it will write to&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;props.conf needs to be defined on the indexer&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;It needs to define how to parse the data by sourcetype that it receives&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;indexes.conf needs to be defined on the indexer&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;It needs to define the basic information for where the data should be stored&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 23 Apr 2013 18:52:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexing-logs-to-remote-server/m-p/104420#M21993</guid>
      <dc:creator>aholzer</dc:creator>
      <dc:date>2013-04-23T18:52:53Z</dc:date>
    </item>
  </channel>
</rss>

