Getting Data In

Cluster Master Send Internal Logs To Indexer

Ne_phil
Loves-to-Learn Lots

Hi Splunk Community --

I'm trying to ensure that my cluster master is sending internal logs to the indexer. Which directory in my cluster master should I put outputs. conf? And are there other conf files that should accompany my outputs.conf file?

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Ne_phil,

Why shoud you use an outputs.conf to send Master Node's logs to indexers?

it's a single machine, you can easily configure forwarding by GUI [Settings > Forwardring and Receiving > Forwardring] and Splunk will send all logs, without thinking to which folders having to monitor.

Ciao.

Giuseppe

 

0 Karma

Ne_phil
Loves-to-Learn Lots

in our environment our cluster master (master node) and indexers (peer nodes) are all on separate servers and we are trying to set it up from backend instead of the GUI.

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Ho @Ne_phil 

as a best pratcice create app in location $SPLUNK_HOME/etc/apps/ 

ex: clm_forwarder_outputs--->local--->outputs.conf 

add indexer ips and restart splunk

0 Karma

Ne_phil
Loves-to-Learn Lots

I’m not following the example but placing the app in$SPLUNK_HOME/etc/apps makes sense.

But why not just put the outputs.conf in $SPLUNK_HOME/etc/system/local?

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @Ne_phil 
even $SPLUNK_HOME/etc/system/local location 

also works,  but from etc/apps/ it can be managed globally if you place it etc/apps/.

either ways its works

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...