<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to index data from a single server when the log path is in a shared drive? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-index-data-from-a-single-server-when-the-log-path-is-in-a/m-p/309094#M58152</link>
    <description>&lt;P&gt;Hi All, I am facing the below issue:&lt;/P&gt;

&lt;P&gt;I am reading few log sources (monitor) from the 3 servers, Server1, Server2 and Server3.&lt;BR /&gt;
Along with that, I am also reading a log source (test1.txt) from a shared path (This path is shared across all 3 servers).&lt;BR /&gt;
Now, the issue is: the same log source (test1.txt) is indexed twice on Splunk against the host Server2 and Server3.&lt;BR /&gt;
Whereas, I want to index this source only once against the server Server1 and not to index for Server2 and Server3.&lt;BR /&gt;
Is there a way in config file where I can specify that test1.txt should be monitored only from Server1. &lt;BR /&gt;
How can I achieve this? Please help me. regards, Santosh&lt;/P&gt;</description>
    <pubDate>Tue, 17 Oct 2017 07:21:29 GMT</pubDate>
    <dc:creator>santosh_hb</dc:creator>
    <dc:date>2017-10-17T07:21:29Z</dc:date>
    <item>
      <title>How to index data from a single server when the log path is in a shared drive?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-index-data-from-a-single-server-when-the-log-path-is-in-a/m-p/309094#M58152</link>
      <description>&lt;P&gt;Hi All, I am facing the below issue:&lt;/P&gt;

&lt;P&gt;I am reading few log sources (monitor) from the 3 servers, Server1, Server2 and Server3.&lt;BR /&gt;
Along with that, I am also reading a log source (test1.txt) from a shared path (This path is shared across all 3 servers).&lt;BR /&gt;
Now, the issue is: the same log source (test1.txt) is indexed twice on Splunk against the host Server2 and Server3.&lt;BR /&gt;
Whereas, I want to index this source only once against the server Server1 and not to index for Server2 and Server3.&lt;BR /&gt;
Is there a way in config file where I can specify that test1.txt should be monitored only from Server1. &lt;BR /&gt;
How can I achieve this? Please help me. regards, Santosh&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2017 07:21:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-index-data-from-a-single-server-when-the-log-path-is-in-a/m-p/309094#M58152</guid>
      <dc:creator>santosh_hb</dc:creator>
      <dc:date>2017-10-17T07:21:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to index data from a single server when the log path is in a shared drive?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-index-data-from-a-single-server-when-the-log-path-is-in-a/m-p/309095#M58153</link>
      <description>&lt;P&gt;Hi santosh_hb,&lt;BR /&gt;
probably you used the same inputs.conf in all the servers, you could use a different one on server1 (with monitoring of test1.txt) than the other two servers (without monitoring of test1.txt).&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2017 08:48:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-index-data-from-a-single-server-when-the-log-path-is-in-a/m-p/309095#M58153</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-10-17T08:48:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to index data from a single server when the log path is in a shared drive?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-index-data-from-a-single-server-when-the-log-path-is-in-a/m-p/309096#M58154</link>
      <description>&lt;P&gt;Hi Giuseppe, Thanks for the reply.  This works fine. I wanted to know if there is any other alternative way where I can just add/modify a single inputs.conf which can be pushed to all 3 servers without pushing separate inputs.conf for server1 and server2 and so-on. &lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2017 07:08:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-index-data-from-a-single-server-when-the-log-path-is-in-a/m-p/309096#M58154</guid>
      <dc:creator>santosh_hb</dc:creator>
      <dc:date>2017-10-23T07:08:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to index data from a single server when the log path is in a shared drive?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-index-data-from-a-single-server-when-the-log-path-is-in-a/m-p/309097#M58155</link>
      <description>&lt;P&gt;Hi,Did you find solution for that? I need to have common inputs across all servers?&lt;/P&gt;</description>
      <pubDate>Tue, 19 May 2020 12:56:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-index-data-from-a-single-server-when-the-log-path-is-in-a/m-p/309097#M58155</guid>
      <dc:creator>hemendralodhi</dc:creator>
      <dc:date>2020-05-19T12:56:55Z</dc:date>
    </item>
  </channel>
</rss>

