Getting Data In

Universal Forwarder - Add another Log FIle to Index

pgergen
New Member

Hi

I have a Linux Splunk Indexer.

How do I add another log file to be indexed by Splunk to the Universal Forwarder on a Windows Server ?

Many Thanks

Regards
Peta Gergen
[email protected]

0 Karma

lalit_mohan
Path Finder

Hi Guys,

I have similar problem!!!

I have two instances one is splunk-server and other is splunk-forwarder(universalForwarder).
Everything is fine with configuration ,then I tried to monitor tomcat logs and I have perform below steps on forwarder.

/usr/share/splunk_setup/splunkforwarder/bin/splunk add monitor /usr/share/apache-tomcat-7.0.42/logs/catalina.out -index default -sourcetype log4j -hostname splunkforwarder

But in search tab of splunk-web I always get No results found.

Am I missing something !!!.Please help me out.
Thanks in advance!!

0 Karma

Ayn
Legend

There's a whole manual covering these topics in the docs. This should be a good place to start: http://docs.splunk.com/Documentation/Splunk/latest/Data/Configureyourinputs

Long story short: either use the CLI or add a directive in in an inputs.conf file (for instance in $SPLUNK_HOME/etc/system/local).

CLI: $SPLUNK_HOME/bin/splunk add monitor <logdir>

inputs.conf: [monitor:///<logdir>]

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – August 2026

MichelleCorpora_1-1788182384472.png Welcome to the August 2026 edition of Data Management Digest! August was a ...

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...