<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to configure universal forwarder on Linux to send a log file to Splunk heavy forwarder? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-universal-forwarder-on-Linux-to-send-a-log-file/m-p/474919#M81557</link>
    <description>&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 15:39:20 GMT</pubDate>
    <dc:creator>vnguyen46</dc:creator>
    <dc:date>2020-02-21T15:39:20Z</dc:date>
    <item>
      <title>How to configure universal forwarder on Linux to send a log file to Splunk heavy forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-universal-forwarder-on-Linux-to-send-a-log-file/m-p/474917#M81555</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
I installed and configured UF on a Linux server to send syslog to Splunk HF. I am now trying to send an application log also on the same server, say it's in /opt/application/applog.log, to the HF. What I need to modify on the UF .conf file(s) ?&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2020 19:42:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-universal-forwarder-on-Linux-to-send-a-log-file/m-p/474917#M81555</guid>
      <dc:creator>vnguyen46</dc:creator>
      <dc:date>2020-02-20T19:42:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure universal forwarder on Linux to send a log file to Splunk heavy forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-universal-forwarder-on-Linux-to-send-a-log-file/m-p/474918#M81556</link>
      <description>&lt;P&gt;If universal forwarder is already connecting to heavy forwarder then you can just add a MONITOR input to forward applog.log in inputs.conf on &lt;STRONG&gt;UF&lt;/STRONG&gt;.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///opt/application/applog.log]
disabled = false
index = &amp;lt;index_name&amp;gt;
sourcetype = &amp;lt;sourcetype_name&amp;gt;
crcSalt = 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 20 Feb 2020 21:08:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-universal-forwarder-on-Linux-to-send-a-log-file/m-p/474918#M81556</guid>
      <dc:creator>manjunathmeti</dc:creator>
      <dc:date>2020-02-20T21:08:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure universal forwarder on Linux to send a log file to Splunk heavy forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-universal-forwarder-on-Linux-to-send-a-log-file/m-p/474919#M81557</link>
      <description>&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:39:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-universal-forwarder-on-Linux-to-send-a-log-file/m-p/474919#M81557</guid>
      <dc:creator>vnguyen46</dc:creator>
      <dc:date>2020-02-21T15:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure universal forwarder on Linux to send a log file to Splunk heavy forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-universal-forwarder-on-Linux-to-send-a-log-file/m-p/474920#M81558</link>
      <description>&lt;P&gt;you are welcome &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 20:00:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-universal-forwarder-on-Linux-to-send-a-log-file/m-p/474920#M81558</guid>
      <dc:creator>manjunathmeti</dc:creator>
      <dc:date>2020-02-21T20:00:45Z</dc:date>
    </item>
  </channel>
</rss>

