Getting Data In

Cluster Master Send Internal Logs To Indexer

Ne_phil
Loves-to-Learn Lots

Hi Splunk Community --

I'm trying to ensure that my cluster master is sending internal logs to the indexer. Which directory in my cluster master should I put outputs. conf? And are there other conf files that should accompany my outputs.conf file?

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Ne_phil,

Why shoud you use an outputs.conf to send Master Node's logs to indexers?

it's a single machine, you can easily configure forwarding by GUI [Settings > Forwardring and Receiving > Forwardring] and Splunk will send all logs, without thinking to which folders having to monitor.

Ciao.

Giuseppe

 

0 Karma

Ne_phil
Loves-to-Learn Lots

in our environment our cluster master (master node) and indexers (peer nodes) are all on separate servers and we are trying to set it up from backend instead of the GUI.

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Ho @Ne_phil 

as a best pratcice create app in location $SPLUNK_HOME/etc/apps/ 

ex: clm_forwarder_outputs--->local--->outputs.conf 

add indexer ips and restart splunk

0 Karma

Ne_phil
Loves-to-Learn Lots

I’m not following the example but placing the app in$SPLUNK_HOME/etc/apps makes sense.

But why not just put the outputs.conf in $SPLUNK_HOME/etc/system/local?

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @Ne_phil 
even $SPLUNK_HOME/etc/system/local location 

also works,  but from etc/apps/ it can be managed globally if you place it etc/apps/.

either ways its works

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...