Hello,
We have installed Splunk on our rsyslogd server and would like to parse all the rsyslog data to Splunk.
Can I configure as below to collect the data locally ?
*.* @@127.0.0.1
Do I need to anything else except, adding the above line?
It is typically done like this (which is how we always do it):
http://www.georgestarcher.com/splunk-success-with-syslog/