Getting Data In
Highlighted

Monitor Universal forwarder

Path Finder

Hello all,

I have somme issue with my universal forwarder and I would like to monitor the logs file of my forwader (metrics.log, splunkd.log, ...) from the indexer to see what's wrong.
Is there a way in a outputs.conf to forward this logs file to the indexer ? Or we need to put [monitor:///opt/splunk/var/log/splunk/metrics] and [monitor:///opt/splunk/var/log/splunk/splunkd] on the inputs.conf file.

Thanks a lot

LudoZ

Tags (1)
Highlighted

Re: Monitor Universal forwarder

Communicator

Using the inputs.conf on the forwarder side sounds like a good option.
You should, push it to a specific index so that it doesn't fall into the main one.

View solution in original post

Highlighted

Re: Monitor Universal forwarder

Path Finder

Make sure that you put index=_internal in your search if you are trying to query the splunkd.log files. I could not see mine even signed on as admin and starting the search with index="*"

0 Karma