I have the question about splunkforwarder , so hope someone can help me !
I successfully used to transfer logs , as follows
host = 10.10.203.1
disabled = 0
sourcetype = http_access_log
defaultGroup = 10.10.203.7_9997
server = 10.10.203.7:9997
But if i want to change to UDP 514 , i search and read documents, i cant understand how to do it correctly .
I read the http://docs.splunk.com/Documentation/Splunk/5.0/SearchReference/Outputtext, but where to use the syntax of outputtext , command or others ?
I think you're confusing concepts quite a bit here. Outputtext is a command used in searches that does something else entirely.
Light and universal forwarders cannot send syslog data. More information in the syslog part of the outputs.conf documentation here: http://docs.splunk.com/Documentation/Splunk/5.0/Admin/Outputsconf
Another sample as follows,
defaultGroup = 10.10.203.7_514
server = 10.10.203.514
type = udp
I want to transfer the client's logs to server' s udp 514 port,
but the server does not receive any logs from client's.
client -------------> server:514
Can splunk be ?