Getting Data In

Changed outputs.conf, but why is my Universal Forwarder still sending to the old server, even after a restart?

nce054
Path Finder

I've changed the outputs.conf file on my Universal Forwarder to direct to a different server, and restarted the service. However, I am still receiving the same data on the old server, and nothing on the new server. Am I changing the wrong file? It's in $SPLUNK_HOME\etc\system\local.

0 Karma

harsmarvania57
Ultra Champion

Hi,

Can you please check from which outputs.conf your universal forwarder is taking configuration?

Use below command on universal forwarder, it will display the result, from which file your parameter for outputs.conf is taking value.

$SPLUNK_HOME/bin/splunk cmd btool outputs --debug list

Thanks,
Harshil

0 Karma

nce054
Path Finder

I did this, and the new server is listed as the tcp-out. However, it isn't receiving anything yet, and my old server is still constantly getting new data.

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...