Getting Data In

Cluster Master Send Internal Logs To Indexer

Ne_phil
Loves-to-Learn Lots

Hi Splunk Community --

I'm trying to ensure that my cluster master is sending internal logs to the indexer. Which directory in my cluster master should I put outputs. conf? And are there other conf files that should accompany my outputs.conf file?

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Ne_phil,

Why shoud you use an outputs.conf to send Master Node's logs to indexers?

it's a single machine, you can easily configure forwarding by GUI [Settings > Forwardring and Receiving > Forwardring] and Splunk will send all logs, without thinking to which folders having to monitor.

Ciao.

Giuseppe

 

0 Karma

Ne_phil
Loves-to-Learn Lots

in our environment our cluster master (master node) and indexers (peer nodes) are all on separate servers and we are trying to set it up from backend instead of the GUI.

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Ho @Ne_phil 

as a best pratcice create app in location $SPLUNK_HOME/etc/apps/ 

ex: clm_forwarder_outputs--->local--->outputs.conf 

add indexer ips and restart splunk

0 Karma

Ne_phil
Loves-to-Learn Lots

I’m not following the example but placing the app in$SPLUNK_HOME/etc/apps makes sense.

But why not just put the outputs.conf in $SPLUNK_HOME/etc/system/local?

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @Ne_phil 
even $SPLUNK_HOME/etc/system/local location 

also works,  but from etc/apps/ it can be managed globally if you place it etc/apps/.

either ways its works

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...