Getting Data In

Can universal forwarders detect and forward newly created logs

suhprano
Path Finder

Can Splunk universal forwarders handle and forward newly created log files? I would like to forward data as raw logs to a remote server and not a splunk indexer using the splunk forwarder, but is it smart enough to trigger upon file creation?

Tags (2)
1 Solution

piebob
Splunk Employee
Splunk Employee

if you specify a directory in the inputs.conf being used by the forwarder in question, and the log file is created in that directory, it will get forwarded automatically.

for details about how Splunk monitors files and directories: http://www.splunk.com/base/Documentation/latest/Data/Monitorfilesanddirectories

details on how forwarders can get data: http://www.splunk.com/base/Documentation/latest/Data/Usingforwardingagents

i missed that you were talking about forwarding to a third-party (not splunk) host, here is the info for that:

http://www.splunk.com/base/Documentation/latest/Deploy/Forwarddatatothird-partysystemsd

View solution in original post

piebob
Splunk Employee
Splunk Employee

if you specify a directory in the inputs.conf being used by the forwarder in question, and the log file is created in that directory, it will get forwarded automatically.

for details about how Splunk monitors files and directories: http://www.splunk.com/base/Documentation/latest/Data/Monitorfilesanddirectories

details on how forwarders can get data: http://www.splunk.com/base/Documentation/latest/Data/Usingforwardingagents

i missed that you were talking about forwarding to a third-party (not splunk) host, here is the info for that:

http://www.splunk.com/base/Documentation/latest/Deploy/Forwarddatatothird-partysystemsd

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...