Getting Data In

Question about configuring the Master Node to forward OS logs

Explorer

Reading OS logs from a cluster indexer node is controlled by the master node $SPLUNKHOME/etc/master-apps/cluster/local/inputs.conf , but that only affects the indexer nodes, not the master node itself.

If I configure outputs.conf in $SPLUNK_HOME/etc/system/local/ on the master node, will it then forward everything from the master node or only the monitored paths specified in inputs.conf ?

The thing is that I only want to forward OS logs (under /var/log or any other specified file), not the internal stuff from Splunk on the master node itself.

0 Karma

Path Finder

I would suggest a manual edit or deployment of *NIX App. Using deployment server.

0 Karma