- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How can I use a universal forwarder to send log files in specific directory to ArcSight?
bgamblin
Explorer
08-07-2015
07:04 AM
I am already sending *.debug syslog data to an ArcSight connector in rsyslog.conf. Now they want to monitor some application logs in a specific directory. I have installed the universal forwarder, but not really sure how to setup inputs.conf and outputs.conf to send the log files. Any help is greatly appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
khourihan_splun

Splunk Employee
08-07-2015
07:11 AM
Hey B,
You can use monitor input's in your inputs.conf file, or use the CLI. See example 5 here.
Regarding outputs.conf, you want to add something like this into $SPLUNK_HOME/system/local/outputs.conf:
[tcpout]
defaultGroup=my_indexers
[tcpout:my_indexers]
server=mysplunk_indexer1:9997, mysplunk_indexer2:9997
autoLB = true
More info here.
Remember when editing .conf file, you need to restart the forwarder afterwards.
i.e. #splunk restart
Hope this helps,
Kyle
