Getting Data In

Monitor Splunk Indexer OS Logs - Port Conflicts?

aferone
Builder

I want to monitor /var/log on all of my Splunk Indexers. However, when I configured this, I was then getting issues connecting to my Heavy Forwarders. I configured an outputs.conf to send the logs to the Heavy Forwarders, then back to the Indexers. This probably doesn't sound right.

How would this be accomplished?

Thanks!

P.S. How would I monitor the /var/log on my Heavy Forwards, Search Heads, etc?

0 Karma
1 Solution

aferone
Builder

I think I have it working by not specifying any outputs.conf on the Indexers.

View solution in original post

0 Karma

aferone
Builder

I think I have it working by not specifying any outputs.conf on the Indexers.

0 Karma

aferone
Builder

I think I have it working by not specifying any outputs.conf on the Indexers.

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...