Getting Data In

Changed outputs.conf, but why is my Universal Forwarder still sending to the old server, even after a restart?

nce054
Path Finder

I've changed the outputs.conf file on my Universal Forwarder to direct to a different server, and restarted the service. However, I am still receiving the same data on the old server, and nothing on the new server. Am I changing the wrong file? It's in $SPLUNK_HOME\etc\system\local.

0 Karma

harsmarvania57
Ultra Champion

Hi,

Can you please check from which outputs.conf your universal forwarder is taking configuration?

Use below command on universal forwarder, it will display the result, from which file your parameter for outputs.conf is taking value.

$SPLUNK_HOME/bin/splunk cmd btool outputs --debug list

Thanks,
Harshil

0 Karma

nce054
Path Finder

I did this, and the new server is listed as the tcp-out. However, it isn't receiving anything yet, and my old server is still constantly getting new data.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...