Getting Data In

Splunkforwarder - log to file?

panulpet
Loves-to-Learn

Hi,

Is it possible to forward logs to indexer and at the same forward logs locally to a new file? I mean forwarder would crete a new file and put indexed data there..

Thanks
-Pete

0 Karma

saramamurthy_sp
Splunk Employee
Splunk Employee

If you are question is , when the forwarder forwards a data to a indexer and these data will be forwarded into a different folder, then I am sorry this wont happen.

Forwarder only forwards the data to the indexer,you can forward the same data to multiple process, but you cant forward the indexed data to a different file or location.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I'm not aware of such a feature. Why do you need it? What problem are you trying to solve?

---
If this reply helps you, Karma would be appreciated.
0 Karma

panulpet
Loves-to-Learn

Hi, This question came from Our customer.. I need to find out what they are trying to solve with this setup 🙂

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

  Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...