I checked out the new Universal Forwarder and ran into some problems that I dont understand.
First I configured the forwarder by creating a "output.conf" and "input.conf" in /opt/splunkforwarder/etc/system/local.
The content of output.conf:
The content of input.conf:
I got some errors in the splunkd.log that I dont understand:
05-03-2011 15:35:14.993 +0000 WARN TcpOutputProc - Pipeline data does not have indexKey. [path] = /var/log/apache2/modsecaudit.log