I am not sure about this, it's very tricky. Can anyone help me on this?
Do I need to update any .conf files?
Do you have a fresh install of Splunk? If so, you need to enable your Indexer to listen on port 9997
. Once that's done you then need to use your deployment server (or login to the machine with the forwarder installed) and edit the inputs.conf
to monitor a file and have an outputs.conf
to tell the forwarder where to send the data to
https://docs.splunk.com/Documentation/SplunkCloud/6.6.1/Forwarding/Enableareceiver
identify the index under the monitoring stanza in inputs.conf
[monitor:///my_stuff]
index = my_stuuf_index