Getting Data In

Splunk forwarder, how can I forward data to some port with some index name and different sourcetypes for different files?

axl88
Communicator

Splunk forwarder, how can I forward data to same port at different server with same index name and different sourcetypes for different files?

Moreover all above is possible in light forwarder?
Could you give an example for changes on .conf files?
**Like
myindex appAsourcetype
myindex appBsourcetype
secondindex appCsourcetype (this is not a must, just extra knowledge if someone knows)

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

The Universal Forwarder can have index and sourcetype defined for its sources. The definition works in inputs.conf just like on a standalone Splunk instance. You'll find documentation here: http://docs.splunk.com/Documentation/Splunk/6.0.3/Data/Editinputs.conf

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...