Getting Data In

Cluster Master Send Internal Logs To Indexer

Ne_phil
Loves-to-Learn Lots

Hi Splunk Community --

I'm trying to ensure that my cluster master is sending internal logs to the indexer. Which directory in my cluster master should I put outputs. conf? And are there other conf files that should accompany my outputs.conf file?

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Ne_phil,

Why shoud you use an outputs.conf to send Master Node's logs to indexers?

it's a single machine, you can easily configure forwarding by GUI [Settings > Forwardring and Receiving > Forwardring] and Splunk will send all logs, without thinking to which folders having to monitor.

Ciao.

Giuseppe

 

0 Karma

Ne_phil
Loves-to-Learn Lots

in our environment our cluster master (master node) and indexers (peer nodes) are all on separate servers and we are trying to set it up from backend instead of the GUI.

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Ho @Ne_phil 

as a best pratcice create app in location $SPLUNK_HOME/etc/apps/ 

ex: clm_forwarder_outputs--->local--->outputs.conf 

add indexer ips and restart splunk

0 Karma

Ne_phil
Loves-to-Learn Lots

I’m not following the example but placing the app in$SPLUNK_HOME/etc/apps makes sense.

But why not just put the outputs.conf in $SPLUNK_HOME/etc/system/local?

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @Ne_phil 
even $SPLUNK_HOME/etc/system/local location 

also works,  but from etc/apps/ it can be managed globally if you place it etc/apps/.

either ways its works

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...