Getting Data In

How to index data from a single server when the log path is in a shared drive?

santosh_hb
Explorer

Hi All, I am facing the below issue:

I am reading few log sources (monitor) from the 3 servers, Server1, Server2 and Server3.
Along with that, I am also reading a log source (test1.txt) from a shared path (This path is shared across all 3 servers).
Now, the issue is: the same log source (test1.txt) is indexed twice on Splunk against the host Server2 and Server3.
Whereas, I want to index this source only once against the server Server1 and not to index for Server2 and Server3.
Is there a way in config file where I can specify that test1.txt should be monitored only from Server1.
How can I achieve this? Please help me. regards, Santosh

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi santosh_hb,
probably you used the same inputs.conf in all the servers, you could use a different one on server1 (with monitoring of test1.txt) than the other two servers (without monitoring of test1.txt).

Bye.
Giuseppe

View solution in original post

santosh_hb
Explorer

Hi Giuseppe, Thanks for the reply. This works fine. I wanted to know if there is any other alternative way where I can just add/modify a single inputs.conf which can be pushed to all 3 servers without pushing separate inputs.conf for server1 and server2 and so-on.

0 Karma

hemendralodhi
Contributor

Hi,Did you find solution for that? I need to have common inputs across all servers?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi santosh_hb,
probably you used the same inputs.conf in all the servers, you could use a different one on server1 (with monitoring of test1.txt) than the other two servers (without monitoring of test1.txt).

Bye.
Giuseppe

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...