I have installed splunkforwarder-6.0.3 on windows server and configured .conf as below. Please let me know if am missing anything.
[monitor:://C:\Program Files (x86)\Hitachi ID\Telephone Password Manager\Logs\TEST-PSYNCH\idmsuite.log]
disabled = 0
sourcetype = mysourcetype
host = myhostname
autoLB = true
compressed = false
defaultGroup = wdc
server = servername.com:9997,servername.com:9997
This is first time i have installed splunk. Do i need to configure anything from indexer side?
Yup, you have to configure your indexer to receive data from your universal forwarder. Check out this documentation on enabling your receiver/indexer: