- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Want to analyse all linux connected system logs on real time basis so please tell me the configuration of using forwarder.
kunalagarwal
New Member
01-10-2013
04:48 AM
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
sdaniels

Splunk Employee
01-10-2013
05:40 AM
You'll want to install the Universal forwarder on each linux server. Then set up a monitor for the log files (/var/log/ folder) and forward to the indexer. On the indexer you'll need to enable receiving in the manager. See our docs below.
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Aboutforwardingandreceivingdata http://docs.splunk.com/Documentation/Splunk/latest/Data/Monitorfilesanddirectories
