Hello, fairly new to splunk. I have 3 servers that all have text based log files on them. We need to monitor those log entries for specific strings, and email us when that string appears. What do I need to have installed on those servers to monitor those log files? Forwarder? Or something else. And then how do we get around the fact that the log file names keep changing? Watch the directory, I suppose.
Lastly, what are the the partition requirements for splunk...I would like to put the main splunk server on D:, and I need to know if I should boost the D; drive space.
Thank you Very Much!